#VU126190 Buffer over-read in Qualcomm products - CVE-2026-21367

 

#VU126190 Buffer over-read in Qualcomm products - CVE-2026-21367

Published: April 15, 2026


Vulnerability identifier: #VU126190
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2026-21367
CWE-ID: CWE-126
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
AR8035
Cologne
CSR8811
FastConnect 6200
FastConnect 6700
FastConnect 6900
FastConnect 7800
FWA Gen 3 Ultra Platform
G2 Gen 1
Immersive Home 214 Platform
Immersive Home 216 Platform
Immersive Home 316 Platform
Immersive Home 318 Platform
IPQ5010
IPQ5028
IPQ6000
IPQ6010
IPQ6018
IPQ8076
IPQ8078
IPQ9574
Milos
Netrani
Networking Pro 1200 Platform
Networking Pro 1210 Platform
Networking Pro 1610 Platform
Networking Pro 400 Platform
Networking Pro 600 Platform
Networking Pro 610 Platform
Networking Pro 800 Platform
Networking Pro 810 Platform
Orne
Palawan25
Pandeiro
QCA4024
QCA6391
QCA6698AU
QCA6777AQ
QCA6787AQ
QCA6797AQ
QCA8075
QCA8081
QCA8082
QCA8084
QCA8085
QCA8337
QCA8386
QCA9888
QCA9889
QCC2073
QCC2076
QCC710
QCM4490
QCN5022
QCN5024
QCN5052
QCN5122
QCN5124
QCN5152
QCN5154
QCN5164
QCN6023
QCN6024
QCN6122
QCN6224
QCN6274
QCN9000
QCN9011
QCN9012
QCN9022
QCN9024
QCN9070
QCN9100
QCN9274
QCS4490
QCS8550
QFW7114
QFW7124
QLN1083BD
QLN1086BD
QMP1000
QPA1083BD
QPA1086BD
QXM1093
QXM1094
QXM1095
QXM1096
SAR2130P
SC8380XP
SD 8 Gen1 5G
SM6650P
SM7435
SM7635P
SM7675
SM7675P
SM8635
SM8635P
SM8650Q
SM8750P
Snapdragon 6 Gen 1 Mobile Platform
Snapdragon 6 Gen 3 Mobile Platform
Snapdragon 6 Gen 4 Mobile Platform
Snapdragon 7 Gen 1 Mobile Platform
Snapdragon 7+ Gen 2 Mobile Platform
Snapdragon 7s Gen 3 Mobile Platform
Snapdragon 8 Elite
Snapdragon 8 Elite Gen 5
Snapdragon 8 Gen 1 Mobile Platform
Snapdragon 8 Gen 3 Mobile Platform
Snapdragon 8+ Gen 1 Mobile Platform
Snapdragon X72 5G Modem-RF System
Snapdragon X75 5G Modem-RF System
WCD9340
WCD9370
WCD9375
WCD9378
WCD9378C
WCD9380
WCD9385
WCD9390
WCD9395
WCN3950
WCN3988
WCN6450
WCN6650
WCN6755
WCN7860
WCN7861
WCN7880
WCN7881
WSA8810
WSA8815
WSA8830
WSA8835
WSA8840
WSA8845
WSA8845H
X2000077
X2000086
X2000090
X2000092
X2000094
XG101002
XG101032
XG101039
XRV7209
XRV9209
QCN6132
SM8475P
WSA8832
Software vendor:
Qualcomm

Description

The vulnerability allows a remote privileged application to execute arbitrary code.

The vulnerability exists due to improper input validation in WLAN Firmware. A remote privileged application can execute arbitrary code.


Remediation

Install security update from vendor's website.

External links