Improper input validation in Qualcomm products - CVE-2020-11202
Published: July 7, 2025 / Updated: July 7, 2025
Vulnerability identifier: #VU112424
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-11202
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability:
Public exploit is available
Vulnerability details
The vulnerability allows a local application to execute arbitrary code.
The vulnerability exists due to improper input validation in Video. A local application can execute arbitrary code.
Affected software
SDM710
SM8150
SM7150
SM6150
SDX55
SDM845
SDM670
SDA845
SA6155P
QCS605
SM8150P
SM7150P
SM7125
SM6250P
SM6250
SM6150P
SM6125
SDX55M
SDX50M
SDM830
QCM6125
SDM640
SDA670
SDA640
SA8155P
SA8155
SA6155
SA6145P
QCS6125
QCS610
QCS603
QCS410
SM8150
SM7150
SM6150
SDX55
SDM845
SDM670
SDA845
SA6155P
QCS605
SM8150P
SM7150P
SM7125
SM6250P
SM6250
SM6150P
SM6125
SDX55M
SDX50M
SDM830
QCM6125
SDM640
SDA670
SDA640
SA8155P
SA8155
SA6155
SA6145P
QCS6125
QCS610
QCS603
QCS410
How to mitigate CVE-2020-11202
Install security update from vendor's website.