OPPO Mobile Telecommunication Corp., Ltd.

First CVE: Apr 21, 2020Active for: 6 years
25
CVEs Published
More CVEs Published than 45% of tracked CNAs
3.6
Avg CVEs / Year
More Avg CVEs / Year than 26% of tracked CNAs
7.8
Avg CVSS Score
Higher Avg CVSS Score than 82% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by OPPO Mobile Telecommunication Corp., Ltd. as a CNA, 68.0% affect products that OPPO Mobile Telecommunication Corp., Ltd. develops as a vendor.

68.0%
32.0%
Self-reported: 17Third-party: 8

Of all the CVEs published that affect products developed by OPPO Mobile Telecommunication Corp., Ltd., 94.4% are self-published by OPPO Mobile Telecommunication Corp., Ltd. as a CNA.

94.4%
Self-published: 17Published by other CNAs: 1

Trends Over Time

The number and severity of CVEs published by OPPO Mobile Telecommunication Corp., Ltd. over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 21, 2020
6 years ago
Most Recent CVE
Jun 29, 2026
25 days ago

Top CVEs

All CVEs published by OPPO Mobile Telecommunication Corp., Ltd. as a CNA, regardless of affected vendor or product.

25 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
ColorOS Assistant has an unauthenticated start-download channel, leading to file path traversal.
Apr 30, 20269.835NONO
Because O+ Connect's IPC service does not authenticate clients, external applications can escalate privileges and perform sensitive actions through the IPC channel.
Jun 29, 20267.333NONO
A command injection vulerability found in quick game engine allows arbitrary remote code in quick app. Allows remote attacke0rs to gain arbitrary code execution in quick game engin
Apr 1, 20229.830NONO
There is a command injection problem in the old version of the mobile phone backup app.
Aug 9, 20239.829NONO
QualityProtect has a vulnerability to execute arbitrary system commands, affected product is com.oppo.qualityprotect V2.0.
Nov 19, 20209.829NONO
In OPPO Store APP, there's a possible escalation of privilege due to improper input validation.
Dec 18, 20249.828NONO
Dynamic loading of services in the backup and restore SDK leads to elevated privileges, affected product is com.coloros.codebook V2.0.0_5493e40_200722.
Nov 19, 20209.828NONO
Loading arbitrary external URLs through WebView components introduces malicious JS code that can steal arbitrary user tokens.
Aug 14, 20258.326NONO
In OPPOStore iOS App, there's a possible escalation of privilege due to improper input validation.
Dec 25, 20248.725NONO
A remote code execution vulnerability in the webview component of OPPO Store app.
Aug 10, 20239.825NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA25 CVEs
Severity distribution among all CVEs352,231 CVEs
MediumHighCritical
Attack Vector
Local10 (40.0%)
Network14 (56.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (4.0%)
Attack Complexity
Low24 (96.0%)
High1 (4.0%)
Unknown0 (0.0%)
User Interaction
None21 (84.0%)
Unknown0 (0.0%)
Required2 (8.0%)
Privileges Required
Low7 (28.0%)
High0 (0.0%)
None18 (72.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (25 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by OPPO Mobile Telecommunication Corp., Ltd. as a CNA.

Media Mentions

Media articles that mention a CVE ID published by OPPO Mobile Telecommunication Corp., Ltd. as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs