Buffer overflow in Qualcomm products - CVE-2020-11130
Published: July 7, 2025
Vulnerability identifier: #VU112433
CSH Severity: Low
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-11130
CWE-ID: CWE-120
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local privileged application to execute arbitrary code.
The vulnerability exists due to improper input validation in WLAN. A local privileged application can execute arbitrary code.
Affected software
SM6115
SXR2130P
SM8350P
SM8350
SM8150P
SM7250P
SM7250
SM7225
SM7125
SM6350
SM6250
SM6125
SM6115P
QCM4290
SM4250P
SM4250
SDX55M
SC8180XP
SA8155P
SA8155
SA6155
SA6145P
QSM8350
QCS4290
SXR2130
SM8250
SM8150
SDX55
SC8180X
SA6155P
QM215
SXR2130P
SM8350P
SM8350
SM8150P
SM7250P
SM7250
SM7225
SM7125
SM6350
SM6250
SM6125
SM6115P
QCM4290
SM4250P
SM4250
SDX55M
SC8180XP
SA8155P
SA8155
SA6155
SA6145P
QSM8350
QCS4290
SXR2130
SM8250
SM8150
SDX55
SC8180X
SA6155P
QM215
How to mitigate CVE-2020-11130
Install security update from vendor's website.