Nq develops a suite of consumer mobile-security and device-management applications, including antivirus, anti-theft, and backup products that handle sensitive user data. Vulnerabilities affecting the vendor skew toward serious outcomes and recur through cryptographic and data-transmission weakness classes, particularly the use of weak cryptographic algorithms and cleartext transmission of sensitive information, reflecting common shortcomings in mobile security software's handling of authentication and user credentials. Live severity, exploitation, and product-coverage details are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Nq over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-15999CRITICAL In the "NQ Contacts Backup & Restore" application 1.1 for Android, no HTTPS is used for transmitting login and synced user data. When logging in, the username is transmitted in cle | Oct 29, 2017 | 9.8 | 29 | NO | NO |
CVE-2017-15997HIGH In the "NQ Contacts Backup & Restore" application 1.1 for Android, RC4 encryption is used to secure the user password locally stored in shared preferences. Because there is a stati | Oct 29, 2017 | 7.8 | 24 | NO | NO |
CVE-2017-15998HIGH In the "NQ Contacts Backup & Restore" application 1.1 for Android, DES encryption with a static key is used to secure transmitted contact data. This makes it easier for remote atta | Oct 29, 2017 | 7.5 | 23 | NO | NO |
CVE-2014-5667MEDIUM The Vault-Hide SMS, Pics & Videos (aka com.netqin.ps) application 5.0.14.22 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attacker | Sep 9, 2014 | 5.4 | 18 | NO | NO |
CVE-2014-5673MEDIUM The Easy Finder & Anti-Theft (aka com.nqmobile.easyfinder) application 2.0.10.08 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle att | Sep 9, 2014 | 5.4 | 17 | NO | NO |
CVE-2014-5672MEDIUM The NQ Mobile Security & Antivirus (aka com.nqmobile.antivirus20) application 7.2.16.00 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-mid | Sep 9, 2014 | 5.4 | 17 | NO | NO |
CVE-2014-5764MEDIUM The Antivirus Free (aka com.zrgiu.antivirus) application 7.2.16.02 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoo | Sep 9, 2014 | 5.4 | 15 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Nq.
Media articles that mention a CVE ID that affects a product developed by Nq — matched by CVE ID, not by vendor name.