In Snapdragon (Automobile, Mobile, Wear) in version MDM9206, MDM9607, MDM9640, MDM9650, MSM8996AU, QCA6574AU, QCA6584, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 450, SD 625, SD 650/52, SD 820A, SD 845, SDM429, SDM439, SDM630, SDM632, SDM636, SDM660, SDX20, Snapdragon_High_Med_2016, MAC address randomization performed during probe requests is not done properly due to a flawed RNG in use.
Conclusion & alert: CVE-2018-11290 is rated Moderate Risk (49/100): CVSS High severity, with medium exploitation likelihood (EPSS 0.84%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.38% | 0.84% | +0.47% |
| 2 | 2025-12-29 | 0.25% | 0.38% | +0.13% |
| 3 | 2025-08-21 | — | 0.25% | — |
Full EPSS history (8 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.5 | 3.0 | HIGH |
|
3.9 | 3.6 | [email protected] |
| 5.0 | 2.0 | MEDIUM |
|
10.0 | 2.9 | [email protected] |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| qualcomm | mdm9206_firmware | — | cpe:2.3:o:qualcomm:mdm9206_firmware:-:*:*:*:*:*:*:* |
| qualcomm | mdm9607_firmware | — | cpe:2.3:o:qualcomm:mdm9607_firmware:-:*:*:*:*:*:*:* |
| qualcomm | mdm9640_firmware | — | cpe:2.3:o:qualcomm:mdm9640_firmware:-:*:*:*:*:*:*:* |
| qualcomm | mdm9650_firmware | — | cpe:2.3:o:qualcomm:mdm9650_firmware:-:*:*:*:*:*:*:* |
| qualcomm | msm8996au_firmware | — | cpe:2.3:o:qualcomm:msm8996au_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qca6574au_firmware | — | cpe:2.3:o:qualcomm:qca6574au_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sd210_firmware | — | cpe:2.3:o:qualcomm:sd210_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sd212_firmware | — | cpe:2.3:o:qualcomm:sd212_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sd205_firmware | — | cpe:2.3:o:qualcomm:sd205_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sd425_firmware | — | cpe:2.3:o:qualcomm:sd425_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sd427_firmware | — | cpe:2.3:o:qualcomm:sd427_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sd430_firmware | — | cpe:2.3:o:qualcomm:sd430_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sd435_firmware | — | cpe:2.3:o:qualcomm:sd435_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sd450_firmware | — | cpe:2.3:o:qualcomm:sd450_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sd625_firmware | — | cpe:2.3:o:qualcomm:sd625_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sd650_firmware | — | cpe:2.3:o:qualcomm:sd650_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sd652_firmware | — | cpe:2.3:o:qualcomm:sd652_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sd820a_firmware | — | cpe:2.3:o:qualcomm:sd820a_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sd845_firmware | — | cpe:2.3:o:qualcomm:sd845_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sdm429_firmware | — | cpe:2.3:o:qualcomm:sdm429_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sdm439_firmware | — | cpe:2.3:o:qualcomm:sdm439_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sdm630_firmware | — | cpe:2.3:o:qualcomm:sdm630_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sdm632_firmware | — | cpe:2.3:o:qualcomm:sdm632_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sdm636_firmware | — | cpe:2.3:o:qualcomm:sdm636_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sdm660_firmware | — | cpe:2.3:o:qualcomm:sdm660_firmware:-:*:*:*:*:*:*:* |
| qualcomm | sdx20_firmware | — | cpe:2.3:o:qualcomm:sdx20_firmware:-:*:*:*:*:*:*:* |
| qualcomm | qca6584_firmware | — | cpe:2.3:o:qualcomm:qca6584_firmware:-:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| http://support.blackberry.com/kb/articleDetail?language=en_US&articleNumber=000051618 | Not Applicable Third Party Advisory |
| https://source.android.com/security/bulletin/2018-09-01#qualcomm-closed-source-components | Vendor Advisory |
| https://www.qualcomm.com/company/product-security/bulletins | Vendor Advisory |