CVE-2026-21366
7.8 HIGHPublished 2026-08-04 · Updated 2026-08-06
AI risk analysis
- Summary
- The flaw involves memory corruption due to improper handling of packet sizes near the maximum limit, potentially leading to arbitrary code execution.
- Exploitability
- Exploitation requires precise control over packet size and format, making it moderately difficult but feasible with detailed knowledge of the affected firmware.
- Blast radius
- If exploited, this vulnerability could lead to full system compromise affecting devices using these firmwares in critical infrastructure or consumer electronics.
- Prioritized remediation
- Update all affected firmware to the latest versions immediately to mitigate the risk of memory corruption and potential code execution.
memory-corruptionfirmware-updatesecurity-bulletin
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
Memory corruption while processing a packet with a size close to the maximum allowed value.
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-190
Vendors
qualcomm
Products
lemans au lgit firmware, lemans au lgit, lemansau firmware, lemansau, qam8255p firmware, qam8255p, qam8295p firmware, qam8295p, qam8620p firmware, qam8620p, qamsrv1h firmware, qamsrv1h
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.