Doogee develops a range of mobile devices, including rugged and budget-oriented handsets such as the BL5000 and Note59 models, where its disclosed vulnerabilities center on firmware-level input handling and code-integrity issues. The recurring weakness classes—externally controlled resource references, unauthenticated code downloads, and OS command injection—reflect the attack surface inherent to mobile device firmware and the importance of secure boot and signed updates in that context. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Doogee over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-67264HIGH An OS command injection vulnerability in the com.sprd.engineermode component in Doogee Note59, Note59 Pro, and Note59 Pro+ allows a local attacker to execute arbitrary code and esc | Jan 23, 2026 | 7.8 | 28 | NO | NO |
CVE-2016-6564HIGH Android devices with code from Ragentek contain a privileged binary that performs over-the-air (OTA) update checks. Additionally, there are multiple techniques used to hide the exe | Jul 13, 2018 | 8.1 | 23 | NO | NO |
The Doogee BL5000 Android device with a build fingerprint of DOOGEE/BL5000/BL5000:7.0/NRD90M/1497072355:user/release-keys contains a pre-installed app with a package name of com.me | Nov 14, 2019 | 3.3 | 14 | NO | NO |
The Doogee Mix Android device with a build fingerprint of DOOGEE/MIX/MIX:7.0/NRD90M/1495809471:user/release-keys contains a pre-installed app with a package name of com.mediatek.fa | Nov 14, 2019 | 3.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Doogee.
Media articles that mention a CVE ID that affects a product developed by Doogee — matched by CVE ID, not by vendor name.