Adups specializes in firmware-over-the-air (FOTA) update systems deployed across mobile devices and embedded platforms, a narrow but strategically sensitive product line. The vendor's disclosed vulnerability footprint, though modest, reflects the access-control and update-integrity concerns inherent to firmware distribution mechanisms. Current exploitation activity, severity breakdown, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Adups over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-10139HIGH An issue was discovered on BLU R1 HD devices with Shanghai Adups software. The two package names involved in the exfiltration are com.adups.fota and com.adups.fota.sysoper. In the | Jan 13, 2017 | 7.8 | 25 | NO | NO |
CVE-2016-10137HIGH An issue was discovered on BLU R1 HD devices with Shanghai Adups software. The content provider named com.adups.fota.sysoper.provider.InfoProvider in the app with a package name of | Jan 13, 2017 | 7.8 | 25 | NO | NO |
CVE-2016-10138HIGH An issue was discovered on BLU Advance 5.0 and BLU R1 HD devices with Shanghai Adups software. The com.adups.fota.sysoper app is installed as a system app and cannot be disabled by | Jan 13, 2017 | 7.8 | 20 | NO | NO |
CVE-2016-10136HIGH An issue was discovered on BLU R1 HD devices with Shanghai Adups software. The content provider named com.adups.fota.sysoper.provider.InfoProvider in the app with a package name of | Jan 13, 2017 | 7.8 | 20 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Adups.
Media articles that mention a CVE ID that affects a product developed by Adups — matched by CVE ID, not by vendor name.