Platform Packages Modules Wifi vulnerabilities

25 known vulnerabilities affecting platform/packages_modules_wifi.

Total CVEs
25
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
UNKNOWN25

Vulnerabilities

Page 1 of 2
CVE-2025-48524UNKNOWN≥ 16-next:0, < 16-next:2025-09-01≥ 15:0, < 15:2025-09-01+3 more2025-09-01
CVE-2025-48524 CVE-2025-48524: In isSystem of WifiPermissionsUtil In isSystem of WifiPermissionsUtil.java, there is a possible permission bypass due to a missing permission check. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2025-26423UNKNOWN≥ 15-next:0, < 15-next:2025-05-01≥ 15:0, < 15:2025-05-01+2 more2025-05-01
CVE-2025-26423 CVE-2025-26423: In validateIpConfiguration of WifiConfigurationUtil In validateIpConfiguration of WifiConfigurationUtil.java, there is a possible way to trigger a permanent DoS due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-43083UNKNOWN≥ 15-next:0, < 15-next:2024-11-01≥ 12:0, < 12:2024-11-01+3 more2024-11-01
CVE-2024-43083 CVE-2024-43083: In validate of WifiConfigurationUtil In validate of WifiConfigurationUtil.java , there is a possible persistent denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2024-40674UNKNOWN≥ 15-next:0, < 15-next:2024-10-01≥ 14:0, < 14:2024-10-012024-10-01
CVE-2024-40674 CVE-2024-40674: In validateSsid of WifiConfigurationUtil In validateSsid of WifiConfigurationUtil.java, there is a possible way to overflow a system configuration file due to a logic error in the code. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21114UNKNOWN≥ 14-next:0, < 14-next:2024-06-01≥ 13:0, < 13:2024-06-012024-06-01
CVE-2023-21114 CVE-2023-21114: In multiple locations, there is a possible permission bypass due to a confused deputy In multiple locations, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21252UNKNOWN≥ 14-next:0, < 14-next:2023-10-01≥ 12:0, < 12:2023-10-01+2 more2023-10-01
CVE-2023-21252 CVE-2023-21252: In validatePassword of WifiConfigurationUtil In validatePassword of WifiConfigurationUtil.java, there is a possible way to get the device into a boot loop due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-20965UNKNOWN≥ 13-next:0, < 13-next:2023-08-01≥ 13:0, < 13:2023-08-012023-08-01
CVE-2023-20965 CVE-2023-20965: In processMessageImpl of ClientModeImpl In processMessageImpl of ClientModeImpl.java, there is a possible credential disclosure in the TOFU flow due to a logic error in the code. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21242UNKNOWN≥ 13-next:0, < 13-next:2023-08-01≥ 13:0, < 13:2023-08-012023-08-01
CVE-2023-21242 CVE-2023-21242: In isServerCertChainValid of InsecureEapNetworkHandler In isServerCertChainValid of InsecureEapNetworkHandler.java, there is a possible way to trust an imposter server due to a logic error in the code. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21240UNKNOWN≥ 13-next:0, < 13-next:2023-07-01≥ 12:0, < 12:2023-07-01+2 more2023-07-01
CVE-2023-21240 CVE-2023-21240: In Policy of Policy In Policy of Policy.java, there is a possible boot loop due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21243UNKNOWN≥ 13-next:0, < 13-next:2023-07-01≥ 12:0, < 12:2023-07-01+2 more2023-07-01
CVE-2023-21243 CVE-2023-21243: In validateForCommonR1andR2 of PasspointConfiguration In validateForCommonR1andR2 of PasspointConfiguration.java, there is a possible way to inflate the size of a config file with no limits due to a buffer overflow. This could lead to local denial of service with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2023-21027UNKNOWN≥ 13-next:0, < 13-next:2023-06-01≥ 13:0, < 13:2023-06-012023-06-01
CVE-2023-21027 CVE-2023-21027: In multiple functions of PasspointXmlUtils In multiple functions of PasspointXmlUtils.java, there is a possible authentication misconfiguration due to a logic error in the code. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21179UNKNOWN≥ 13-next:0, < 13-next:2023-06-01≥ 13:0, < 13:2023-06-012023-06-01
CVE-2023-21179 CVE-2023-21179: In parseSecurityParamsFromXml of XmlUtil In parseSecurityParamsFromXml of XmlUtil.java, there is a possible bypass of user specified wifi encryption protocol due to improperly used crypto. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21185UNKNOWN≥ 13-next:0, < 13-next:2023-06-01≥ 13:0, < 13:2023-06-012023-06-01
CVE-2023-21185 CVE-2023-21185: In multiple functions of WifiNetworkFactory In multiple functions of WifiNetworkFactory.java, there is a missing permission check. This could lead to local escalation of privilege from the guest user with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20463UNKNOWN≥ 13-next:0, < 13-next:2023-04-01≥ 12:0, < 12:2023-04-01+2 more2023-04-01
CVE-2022-20463 CVE-2022-20463: In factoryReset of WifiServiceImpl In factoryReset of WifiServiceImpl.java, there is a possible way to preserve WiFi settings due to a logic error in the code. This could lead to local non-security issues across resets with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21033UNKNOWN≥ 13:0, < 13:2023-03-012023-03-01
CVE-2023-21033 CVE-2023-21033: In addNetwork of WifiManager In addNetwork of WifiManager.java, there is a possible way to trigger a persistent DoS due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2023-21021UNKNOWN≥ 13:0, < 13:2023-03-012023-03-01
CVE-2023-21021 CVE-2023-21021: In isTargetSdkLessThanQOrPrivileged of WifiServiceImpl In isTargetSdkLessThanQOrPrivileged of WifiServiceImpl.java, there is a possible way for the guest user to change admin user network settings due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20499UNKNOWN≥ 12:0, < 12:2023-03-01≥ 12L:0, < 12L:2023-03-01+1 more2023-03-01
CVE-2022-20499 CVE-2022-20499: In validateForCommonR1andR2 of PasspointConfiguration In validateForCommonR1andR2 of PasspointConfiguration.java, uncaught errors in parsing stored configs could lead to local persistent denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20481UNKNOWN≥ 12:0, < 12:2023-02-01≥ 12L:0, < 12L:2023-02-01+1 more2023-02-01
CVE-2022-20481 CVE-2022-20481: In multiple files, there is a possible way to preserve WiFi settings due to residual data after a reset In multiple files, there is a possible way to preserve WiFi settings due to residual data after a reset. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.
osv
CVE-2022-20240UNKNOWN≥ 12:0, < 12:2022-12-01≥ 12L:0, < 12L:2022-12-012022-12-01
CVE-2022-20240 CVE-2022-20240: In sOpAllowSystemRestrictionBypass of AppOpsManager In sOpAllowSystemRestrictionBypass of AppOpsManager.java, there is a possible leak of location information due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
osv
CVE-2022-20535UNKNOWN≥ 13:0, < 13:2022-12-012022-12-01
CVE-2022-20535 CVE-2022-20535: In registerLocalOnlyHotspotSoftApCallback of WifiManager In registerLocalOnlyHotspotSoftApCallback of WifiManager.java, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
osv