OPPO Mobile Telecommunication Corp., Ltd.
Self-Reporting Analysis
Of all the CVEs published by OPPO Mobile Telecommunication Corp., Ltd. as a CNA, 68.0% affect products that OPPO Mobile Telecommunication Corp., Ltd. develops as a vendor.
Of all the CVEs published that affect products developed by OPPO Mobile Telecommunication Corp., Ltd., 94.4% are self-published by OPPO Mobile Telecommunication Corp., Ltd. as a CNA.
Trends Over Time
The number and severity of CVEs published by OPPO Mobile Telecommunication Corp., Ltd. over time
Top CVEs
All CVEs published by OPPO Mobile Telecommunication Corp., Ltd. as a CNA, regardless of affected vendor or product.
25 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-22070CRITICAL ColorOS Assistant has an unauthenticated start-download channel, leading to file path traversal. | Apr 30, 2026 | 9.8 | 35 | NO | NO |
CVE-2026-22078HIGH Because O+ Connect's IPC service does not authenticate clients, external applications can escalate privileges and perform sensitive actions through the IPC channel. | Jun 29, 2026 | 7.3 | 33 | NO | NO |
CVE-2021-23247CRITICAL A command injection vulerability found in quick game engine allows arbitrary remote code in quick app. Allows remote attacke0rs to gain arbitrary code execution in quick game engin | Apr 1, 2022 | 9.8 | 30 | NO | NO |
CVE-2023-26310CRITICAL There is a command injection problem in the old version of the mobile phone backup app. | Aug 9, 2023 | 9.8 | 29 | NO | NO |
CVE-2020-11830CRITICAL QualityProtect has a vulnerability to execute arbitrary system commands, affected product is com.oppo.qualityprotect V2.0. | Nov 19, 2020 | 9.8 | 29 | NO | NO |
CVE-2024-1610CRITICAL In OPPO Store APP, there's a possible escalation of privilege due to improper input validation. | Dec 18, 2024 | 9.8 | 28 | NO | NO |
CVE-2020-11829CRITICAL Dynamic loading of services in the backup and restore SDK leads to elevated privileges, affected product is com.coloros.codebook V2.0.0_5493e40_200722. | Nov 19, 2020 | 9.8 | 28 | NO | NO |
CVE-2025-27388HIGH Loading arbitrary external URLs through WebView components introduces malicious JS code that can steal arbitrary user tokens. | Aug 14, 2025 | 8.3 | 26 | NO | NO |
CVE-2024-1609HIGH In OPPOStore iOS App, there's a possible escalation of privilege due to improper input validation. | Dec 25, 2024 | 8.7 | 25 | NO | NO |
CVE-2023-26311CRITICAL A remote code execution vulnerability in the webview component of OPPO Store app.
| Aug 10, 2023 | 9.8 | 25 | NO | NO |
CVE Severity & Scoring
Exploit Exposure
Signals from CVEs in this cna scope (25 CVEs).
Social Chatter
An overview of all social media posts that mention a CVE ID published by OPPO Mobile Telecommunication Corp., Ltd. as a CNA.
Media Mentions
Media articles that mention a CVE ID published by OPPO Mobile Telecommunication Corp., Ltd. as a CNA — matched by CVE ID, not by organization name.