cbcvebase.

Platform Packages Modules Wifi vulnerabilities

25 known vulnerabilities affecting platform/packages_modules_wifi.

Total CVEs
25
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
UNKNOWN25

Vulnerabilities

Page 1 of 2
CVE-2023-20965P3UNKNOWN≥ 13-next:0, < 13-next:2023-08-01≥ 13:0, < 13:2023-08-012023-08-01
CVE-2023-20965 CVE-2023-20965: In processMessageImpl of ClientModeImpl In processMessageImpl of ClientModeImpl.java, there is a possible credential disclosure in the TOFU flow due to a logic error in the code. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21242P3UNKNOWN≥ 13-next:0, < 13-next:2023-08-01≥ 13:0, < 13:2023-08-012023-08-01
CVE-2023-21242 CVE-2023-21242: In isServerCertChainValid of InsecureEapNetworkHandler In isServerCertChainValid of InsecureEapNetworkHandler.java, there is a possible way to trust an imposter server due to a logic error in the code. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21027P3UNKNOWN≥ 13-next:0, < 13-next:2023-06-01≥ 13:0, < 13:2023-06-012023-06-01
CVE-2023-21027 CVE-2023-21027: In multiple functions of PasspointXmlUtils In multiple functions of PasspointXmlUtils.java, there is a possible authentication misconfiguration due to a logic error in the code. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21114P3UNKNOWN≥ 14-next:0, < 14-next:2024-06-01≥ 13:0, < 13:2024-06-012024-06-01
CVE-2023-21114 CVE-2023-21114: In multiple locations, there is a possible permission bypass due to a confused deputy In multiple locations, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21185P3UNKNOWN≥ 13-next:0, < 13-next:2023-06-01≥ 13:0, < 13:2023-06-012023-06-01
CVE-2023-21185 CVE-2023-21185: In multiple functions of WifiNetworkFactory In multiple functions of WifiNetworkFactory.java, there is a missing permission check. This could lead to local escalation of privilege from the guest user with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21021P3UNKNOWN≥ 13:0, < 13:2023-03-012023-03-01
CVE-2023-21021 CVE-2023-21021: In isTargetSdkLessThanQOrPrivileged of WifiServiceImpl In isTargetSdkLessThanQOrPrivileged of WifiServiceImpl.java, there is a possible way for the guest user to change admin user network settings due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21179P3UNKNOWN≥ 13-next:0, < 13-next:2023-06-01≥ 13:0, < 13:2023-06-012023-06-01
CVE-2023-21179 CVE-2023-21179: In parseSecurityParamsFromXml of XmlUtil In parseSecurityParamsFromXml of XmlUtil.java, there is a possible bypass of user specified wifi encryption protocol due to improperly used crypto. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20398P3UNKNOWN≥ 13-next:0, < 13-next:2022-09-01≥ 13:0, < 13:2022-09-012022-09-01
CVE-2022-20398 CVE-2022-20398: In addOrUpdateNetwork of WifiServiceImpl In addOrUpdateNetwork of WifiServiceImpl.java, there is a possible way for a guest user to configure Wi-Fi due to a permissions bypass. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-1004P3UNKNOWN≥ 12:0, < 12:2021-12-012021-12-01
CVE-2021-1004 CVE-2021-1004: In getConfiguredNetworks of WifiServiceImpl In getConfiguredNetworks of WifiServiceImpl.java, there is a possible way to determine whether an app is installed, without query permissions, due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-40674P4UNKNOWN≥ 15-next:0, < 15-next:2024-10-01≥ 14:0, < 14:2024-10-012024-10-01
CVE-2024-40674 CVE-2024-40674: In validateSsid of WifiConfigurationUtil In validateSsid of WifiConfigurationUtil.java, there is a possible way to overflow a system configuration file due to a logic error in the code. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-26423P4UNKNOWN≥ 15-next:0, < 15-next:2025-05-01≥ 15:0, < 15:2025-05-01+2 more2025-05-01
CVE-2025-26423 CVE-2025-26423: In validateIpConfiguration of WifiConfigurationUtil In validateIpConfiguration of WifiConfigurationUtil.java, there is a possible way to trigger a permanent DoS due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20481P4UNKNOWN≥ 12:0, < 12:2023-02-01≥ 12L:0, < 12L:2023-02-01+1 more2023-02-01
CVE-2022-20481 CVE-2022-20481: In multiple files, there is a possible way to preserve WiFi settings due to residual data after a reset In multiple files, there is a possible way to preserve WiFi settings due to residual data after a reset. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2025-48524P4UNKNOWN≥ 16-next:0, < 16-next:2025-09-01≥ 15:0, < 15:2025-09-01+3 more2025-09-01
CVE-2025-48524 CVE-2025-48524: In isSystem of WifiPermissionsUtil In isSystem of WifiPermissionsUtil.java, there is a possible permission bypass due to a missing permission check. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21252P4UNKNOWN≥ 14-next:0, < 14-next:2023-10-01≥ 12:0, < 12:2023-10-01+2 more2023-10-01
CVE-2023-21252 CVE-2023-21252: In validatePassword of WifiConfigurationUtil In validatePassword of WifiConfigurationUtil.java, there is a possible way to get the device into a boot loop due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20200P4UNKNOWN≥ 12L-next:0, < 12L-next:2022-06-01≥ 12L:0, < 12L:2022-06-012022-06-01
CVE-2022-20200 CVE-2022-20200: In updateApState of SoftApManager In updateApState of SoftApManager.java, there is a possible leak of hotspot state due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-43083P4UNKNOWN≥ 15-next:0, < 15-next:2024-11-01≥ 12:0, < 12:2024-11-01+3 more2024-11-01
CVE-2024-43083 CVE-2024-43083: In validate of WifiConfigurationUtil In validate of WifiConfigurationUtil.java , there is a possible persistent denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21240P4UNKNOWN≥ 13-next:0, < 13-next:2023-07-01≥ 12:0, < 12:2023-07-01+2 more2023-07-01
CVE-2023-21240 CVE-2023-21240: In Policy of Policy In Policy of Policy.java, there is a possible boot loop due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20499P4UNKNOWN≥ 12:0, < 12:2023-03-01≥ 12L:0, < 12L:2023-03-01+1 more2023-03-01
CVE-2022-20499 CVE-2022-20499: In validateForCommonR1andR2 of PasspointConfiguration In validateForCommonR1andR2 of PasspointConfiguration.java, uncaught errors in parsing stored configs could lead to local persistent denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2021-1026P4UNKNOWN≥ 12:0, < 12:2021-12-012021-12-01
CVE-2021-1026 CVE-2021-1026: In startRanging of RttServiceImpl In startRanging of RttServiceImpl.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21243P4UNKNOWN≥ 13-next:0, < 13-next:2023-07-01≥ 12:0, < 12:2023-07-01+2 more2023-07-01
CVE-2023-21243 CVE-2023-21243: In validateForCommonR1andR2 of PasspointConfiguration In validateForCommonR1andR2 of PasspointConfiguration.java, there is a possible way to inflate the size of a config file with no limits due to a buffer overflow. This could lead to local denial of service with no additional execution privileges needed. User interaction is needed for exploitation.
osv
Platform Packages Modules Wifi vulnerabilities | cvebase