Qcs4490 Firmware
Vendor:
First CVE: May 2, 2023 · Active for 3 years
254
Total CVEs
More Total CVEs than 100% of tracked products
63.5
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
7.6
Avg CVSS
Higher Avg CVSS than 60% of tracked products
2.4%
KEV Rate
Higher KEV Rate than 96% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Qcs4490 Firmware over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 2, 2023
3 years ago
Most Recent CVE
Jul 6, 2026
18 days ago
CVE Severity & Scoring
Qcs4490 Firmware254 CVEs
17%
76%
All CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local150 (59.1%)
Network96 (37.8%)
Unknown0 (0.0%)
Physical5 (2.0%)
Adjacent Network3 (1.2%)
Attack Complexity
Low246 (96.9%)
High8 (3.1%)
Unknown0 (0.0%)
User Interaction
None251 (98.8%)
Unknown0 (0.0%)
Required3 (1.2%)
Privileges Required
Low139 (54.7%)
High10 (3.9%)
None105 (41.3%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (254 CVEs).
254 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-21385HIGH Memory corruption while using alignments for memory allocation. | Mar 2, 2026 | 7.8 | 73 | YES | NO |
CVE-2025-21479HIGH Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands. | Jun 3, 2025 | 8.6 | 69 | YES | NO |
CVE-2025-21480HIGH Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands. | Jun 3, 2025 | 8.6 | 67 | YES | NO |
CVE-2023-33063HIGH Memory corruption in DSP Services during a remote call from HLOS to DSP. | Dec 5, 2023 | 7.8 | 64 | YES | NO |
CVE-2023-33107HIGH Memory corruption in Graphics Linux while assigning shared virtual memory region during IOCTL call. | Dec 5, 2023 | 7.8 | 63 | YES | NO |
CVE-2023-33106HIGH Memory corruption while submitting a large list of sync points in an AUX command to the IOCTL_KGSL_GPU_AUX_COMMAND. | Dec 5, 2023 | 7.8 | 55 | YES | NO |
CVE-2025-59605HIGH Memory Corruption when processing device identifier strings that exceed the expected maximum length. | Jun 1, 2026 | 7.8 | 33 | NO | NO |
CVE-2025-59604HIGH Memory Corruption when running a memory copy operation due to invalid writes caused by a null pointer. | Jun 1, 2026 | 7.8 | 33 | NO | NO |
CVE-2025-27034CRITICAL Memory corruption while selecting the PLMN from SOR failed list. | Sep 24, 2025 | 9.8 | 33 | NO | NO |
CVE-2025-21483CRITICAL Memory corruption when the UE receives an RTP packet from the network, during the reassembly of NALUs. | Sep 24, 2025 | 9.8 | 33 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (254 CVEs).
CISA KEV
6 CVEs
2.4% of CVEs· 96th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (254 CVEs).
Media Mentions
Signals from CVEs in this product scope (254 CVEs).
Top CNAs Publishing CVEs For Qcs4490 Firmware
Top CWEs
Versions
No cataloged versions.