CVE-2026-24081High· 7.4▾ TwilightTransient DOS when processing a channel map with insufficient used channels and adaptive frequency hopping is fully enabled.
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 40.7 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 18.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.2%
Last analysed / modified upstream
Transient DOS when processing a channel map with insufficient used channels and adaptive frequency hopping is fully enabled.
ar8035_firmwarec110100_firmwarecologne_firmwarecq7790_firmwarecq7790m_firmwarewcd9385_firmwarewcd9390_firmwarewcd9395_firmwarewcn3988_firmwarewcn6450_firmwarewcn6650_firmwarewcn6755_firmwarewcn7760_firmwarewcn7860_firmwarewcn7861_firmwarewcn7880_firmwarewcn7881_firmwarewcn8841_firmwarewsa8810_firmwarewsa8815_firmwarewsa8830_firmwarewsa8832_firmwarewsa8835_firmwarewsa8840_firmwarewsa8845_firmwarewsa8845h_firmwarewsa8850_firmwarewsa8850w_firmwarewsa8855c_firmwarex1e80100_firmwarexrv7209_firmwarexrv9209_firmwarecq8725s_firmwarecq8750m_firmwarecq8845s_firmwarefastconnect_6200_firmwarefastconnect_6700_firmwarefastconnect_6900_firmwarefastconnect_7800_firmwarefwa_gen_3_ultra_firmwarefwa_gen_5_elite_firmwareg2_gen_1_firmwareg3x_gen_2_firmwareiq-8275_firmwareiq-9075_firmwareiqx5121_firmwareiqx7181_firmwarekobuk_firmwarembm715_firmwaremilos_firmwaremilos_iot_firmwaremonaco_iot_firmwarenetrani_firmwareorne_firmwarepalawan25_firmwarepandeiro_firmwareq-7790_firmwareqca0000_firmwareqca6391_firmwareqca6698aq_firmwareqca8081_firmwareqca8337_firmwareqca8386_firmwareqcc2070_firmwareqcc2073_firmwareqcc2076_firmwareqcc5161_firmwareqcc6705_firmwareqcc710_firmwareqcc711_firmwareqcc7225_firmwareqcf8001_firmwareqcn6224_firmwareqcn6274_firmwareqcn9011_firmwareqcn9012_firmwareqcs6690_firmwareqcs8550_firmwareqfw7114_firmwareqfw7124_firmwareqln1083bd_firmwareqln1086bd_firmwareqmp1000_firmwareqmp2001_firmwareqpa1083bd_firmwareqpa1086bd_firmwarefastconnect_8800_mobile_connectivity_system_firmwareqxm1083_firmwareqxm1086_firmwareqxm1093_firmwareqxm1094_firmwareqxm1095_firmwareqxm1096_firmwares3_gen_2_sound_platform_firmwares3_sound_platform_firmwares5_gen_2_sound_platform_firmwares5_sound_platform_firmwaresar1165p_firmwaresar2130p_firmwaresc8380xp_firmwareRefer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-24075High· 7.8Memory Corruption when multiple threads issue concurrent IOCTL requests to the device control handler due to improper synchronization and race conditions.
CVE-2026-25275High· 7.5Transient DOS when processing authentication frames with invalid FILS information element header lengths.
CVE-2026-25284High· 7.3Information Disclosure when a pointer is reused after being deallocated.
CVE-2026-25294High· 7.4Transient DOS while parsing frame during channel usage.
CVE-2026-24073High· 7.8Memory corruption when processing decode statistics due to insufficient validation of offset against structure size.
CVE-2026-24074High· 7.8Memory Corruption when processing data with large offset and length values exceeds buffer limits during data copy operations.