CVE-2016-10370 describes a vulnerability in the OnePlus OTA Updater on devices like the 3T, where it transmits signed-OTA images over unencrypted HTTP, affecting OnePlus OxygenOS. This flaw, while not allowing arbitrary OTA installation due to digital signatures, unnecessarily expands the attack surface. It carries a CVSS v3 score of 7.5 (HIGH), indicating a network-based attack with low complexity, potentially leading to high integrity impact, although confidentiality and availability are not directly affected. Despite its high severity, there is no evidence of active exploitation, no known exploit code in Metasploit or ExploitDB, and minimal community discussion, with its EPSS score being very low.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:oneplus:oxygenos:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.