Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Kaiostech

First CVE: Mar 21, 2019Active for: 7 yearsTotal CVEs: 10
19.3
VTI Score
Low

Kaiostech develops a mobile operating system targeting feature phones and entry-level devices, and its vulnerability exposure concentrates in this narrow but strategically important product line. The durable signal centers on web-interaction and command-handling weakness classes—including cross-site scripting, command injection, and resource-exposure issues—that reflect the browser and system-integration surface of a mobile platform. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
10
Total CVEs
More Total CVEs than 92% of tracked vendors
3.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 95% of tracked vendors
5.8
Avg CVSS Score
Higher Avg CVSS Score than 26% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Kaiostech over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 21, 2019
7 years ago
Most Recent CVE
May 22, 2023
1,159 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (10 CVEs).

10 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-33294CRITICAL
An issue was discovered in KaiOS 3.0 before 3.1. The /system/bin/tctweb_server binary exposes a local web server that responds to GET and POST requests on port 2929. The server acc
May 22, 20239.830NONO
CVE-2019-7386MEDIUM
A Denial of Service issue has been discovered in the Gecko component of KaiOS 2.5 10.05 (platform 48.0.a2) on Nokia 8810 4G devices. When a crafted web page is visited with the int
Mar 21, 20196.523NONO
CVE-2019-14757MEDIUM
An issue was discovered in KaiOS 2.5 and 2.5.1. The pre-installed Contacts application is vulnerable to HTML and JavaScript injection attacks. An attacker can send a vCard file to
Sep 14, 20206.122NONO
CVE-2019-14758MEDIUM
An issue was discovered in KaiOS 2.5 and 2.5.1. The pre-installed File Manager application is vulnerable to HTML and JavaScript injection attacks. An attacker can send a file via e
Sep 14, 20206.121NONO
CVE-2019-14756MEDIUM
An issue was discovered in KaiOS 1.0, 2.5, and 2.5.12.5. The pre-installed Email application is vulnerable to HTML and JavaScript injection attacks. An attacker can send a speciall
Sep 14, 20206.121NONO
CVE-2023-27108MEDIUM
An issue was discovered in KaiOS 3.0. The pre-installed Communications application exposes a Web Activity that returns the user's call log without origin or permission checks. An a
May 1, 20235.319NONO
CVE-2023-33293MEDIUM
An issue was discovered in KaiOS 3.0 and 3.1. The binary /system/kaios/api-daemon exposes a local web server on *.localhost with subdomains for each installed applications, e.g., m
May 22, 20235.318NONO
CVE-2019-14761MEDIUM
An issue was discovered in KaiOS 2.5. The pre-installed Note application is vulnerable to HTML and JavaScript injection attacks. A local attacker can inject arbitrary HTML into the
Sep 14, 20204.418NONO
CVE-2019-14760MEDIUM
An issue was discovered in KaiOS 2.5. The pre-installed Recorder application is vulnerable to HTML and JavaScript injection attacks. A local attacker can inject arbitrary HTML into
Sep 14, 20204.418NONO
CVE-2019-14759MEDIUM
An issue was discovered in KaiOS 1.0, 2.5, and 2.5.1. The pre-installed Radio application is vulnerable to HTML and JavaScript injection attacks. A local attacker can inject arbitr
Sep 14, 20204.418NONO
View all 10 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products10 CVEs
90%
10%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumCritical
Attack Vector
Local3 (30.0%)
Network7 (70.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None3 (30.0%)
Unknown0 (0.0%)
Required7 (70.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None10 (100.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (10 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Kaiostech.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Kaiostech — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Kaiostech's Products

View all 1 CNAs →

Top CWEs