CVE Tools

Oneplus

9 CVEs tracked since 2017. Since Mar 2017, none of them reached CISA KEV.

Oneplus CVEs per month

Mar 2017 to May 2017. Point at a month, or focus the strip and use the arrow keys.
Oneplus CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2017-0340
2017-04null or fewer
2017-0550

Products

The products that kept showing up in Oneplus's monthly top three, with their CVEs summed over those months.

  1. Oxygenos82 months
  2. Primary Setup Tool11 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Oneplus.

  1. CVE-2025-10184OnePlus OxygenOS Telephony provider permission bypass7.1
  2. CVE-2023-26309A remote code execution vulnerability in the webview component7.4
  3. CVE-2020-13626OnePlus App Locker through 2020-10-06 allows physically proximate attackers to use Google Assistant to bypass an authorization check in order to send an SMS message when the SMS application is locked.4.6
  4. CVE-2020-7958An issue was discovered on OnePlus 7 Pro devices before 10.0.3.GM21BA. The firmware was found to contain functionality that allows a privileged user (root) in the Rich Execution Environment (REE) t...6.0
  5. CVE-2017-5947An issue was discovered in OnePlus One, X, 2, 3, 3T, and 5 devices with OxygenOS 5.0 and earlier. The attacker can reboot the device into the Qualcomm Emergency Download (EDL) mode through ADB or b...6.8
  6. CVE-2017-11105The OnePlus 2 Primary Bootloader (PBL) does not validate the SBL1 partition before executing it, although it contains a certificate. This allows attackers with write access to that partition to dis...9.8
  7. CVE-2017-5948An issue was discovered on OnePlus One, X, 2, 3, and 3T devices. OxygenOS and HydrogenOS are vulnerable to downgrade attacks. This is due to a lenient 'updater-script' in OTAs that does not check t...5.9
  8. CVE-2017-8851An issue was discovered on OnePlus One and X devices. Due to a lenient updater-script on the OnePlus One and X OTA images, the fact that both products use the same OTA verification keys, and the fa...5.9
  9. CVE-2017-8850An issue was discovered on OnePlus One, X, 2, 3, and 3T devices. Due to a lenient updater-script in the OnePlus OTA images, and the fact that both ROMs use the same OTA verification keys, attackers...5.9
  10. CVE-2016-10370An issue was discovered on OnePlus devices such as the 3T. The OnePlus OTA Updater pushes the signed-OTA image over HTTP without TLS. While it does not allow for installation of arbitrary OTAs (due...7.5
  11. CVE-2017-6865A vulnerability has been identified in Primary Setup Tool (PST) (All versions < V4.2 HF1), SIMATIC Automation Tool (All versions < V3.0), SIMATIC NET PC-Software (All versions < V14 SP1), SIMATIC P...6.5
  12. CVE-2017-5625In OxygenOS before 4.0.3 on OnePlus 3 and 3T devices, an unauthorized attacker can cause a locked bootloader to partially dump the ciphertext content of an arbitrary partition (except 'keystore') b...4.6
  13. CVE-2017-5622With OxygenOS before 4.0.3, when a charger is connected to a powered-off OnePlus 3 or 3T device, the platform starts with adbd enabled. Therefore, a malicious charger or a physical attacker can ope...5.9
  14. CVE-2017-5623An issue was discovered in OxygenOS before 4.1.0 on OnePlus 3 and 3T devices. The attacker can change the bootmode of the device by issuing the 'fastboot oem boot_mode {rf/wlan/ftm/normal} command'...6.6
  15. CVE-2017-5624An issue was discovered in OxygenOS before 4.0.3 for OnePlus 3 and 3T. The attacker can persistently make the (locked) bootloader start the platform with dm-verity disabled, by issuing the 'fastboo...9.8

The record

Peak rank
#72 in May 2017
Busiest month shown
May 2017, 5 CVEs
Months with a KEV entry
0 since Mar 2017
Monthly snapshots
2 since 2017
Oneplus's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store