#VU126199 Buffer over-read in Qualcomm products - CVE-2026-21381

 

#VU126199 Buffer over-read in Qualcomm products - CVE-2026-21381

Published: April 15, 2026


Vulnerability identifier: #VU126199
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2026-21381
CWE-ID: CWE-126
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
AR8035
Cologne
FastConnect 6200
FastConnect 6700
FastConnect 6900
FastConnect 7800
FWA Gen 3 Ultra Platform
G2 Gen 1
Milos
Netrani
Orne
Palawan25
Pandeiro
QCA6391
QCA6698AU
QCA6777AQ
QCA6787AQ
QCA6797AQ
QCA8081
QCA8337
QCC2073
QCC2076
QCC710
QCN6224
QCN6274
QCN9011
QCN9012
QCS8550
QFW7114
QFW7124
QLN1083BD
QLN1086BD
QMP1000
QPA1083BD
QPA1086BD
QXM1083
QXM1086
QXM1093
QXM1094
QXM1095
QXM1096
SAR1165P
SAR2130P
SC8380XP
SM6650P
SM7435
SM7635P
SM7675
SM7675P
SM8635
SM8635P
SM8650Q
SM8750P
Snapdragon 6 Gen 1 Mobile Platform
Snapdragon 6 Gen 3 Mobile Platform
Snapdragon 6 Gen 4 Mobile Platform
Snapdragon 7s Gen 3 Mobile Platform
Snapdragon 8 Elite
Snapdragon 8 Elite Gen 5
Snapdragon 8 Gen 3 Mobile Platform
Snapdragon AR1 Gen 1 Platform
Snapdragon AR1+ Gen 1 Platform
Snapdragon X72 5G Modem-RF System
Snapdragon X75 5G Modem-RF System
SXR2230P
SXR2250P
SXR2330P
SXR2350P
WCD9340
WCD9370
WCD9375
WCD9378
WCD9378C
WCD9380
WCD9385
WCD9390
WCD9395
WCN3988
WCN6450
WCN6650
WCN6755
WCN7860
WCN7861
WCN7880
WCN7881
WSA8810
WSA8815
WSA8830
WSA8835
WSA8840
WSA8845
WSA8845H
X2000077
X2000086
X2000090
X2000092
X2000094
XG101002
XG101032
XG101039
XRV7209
XRV9209
WSA8832
Software vendor:
Qualcomm

Description

The vulnerability allows a remote privileged application to execute arbitrary code.

The vulnerability exists due to improper input validation in WLAN Firmware. A remote privileged application can execute arbitrary code.


Remediation

Install security update from vendor's website.

External links