CVE-2018-11858: Qualcomm Sd 835 Firmware

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

When processing IE set command, buffer overwrite may occur due to lack of input validation of the IE length in Snapdragon Mobile in version SD 835, SD 845, SD 850.

Affected products

  • Qualcomm Sd 835 Firmware: affected versions not specified
  • Qualcomm Sd 845 Firmware: affected versions not specified
  • Qualcomm Sd 850 Firmware: affected versions not specified

Published 2018-10-29. Last modified 2026-06-17.