NTT Docomo's vulnerability profile centers on a focused set of mobile and network connectivity products, including mail applications for Android and Wi-Fi station devices, which are deployed across consumer and enterprise networks in Japan and beyond. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity, and recur through application-layer weakness classes including cross-site request forgery, improper authentication, code injection, cross-site scripting, and memory-buffer handling issues that reflect both web-facing and native code attack surfaces. Defenders should monitor this vendor's advisories for mobile and access-point products and prioritize patching where these devices serve sensitive environments; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Nttdocomo over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-10871CRITICAL Buffer overflow in NTT DOCOMO Wi-Fi STATION L-02F Software version L02F-MDM9625-V10h-JUN-23-2017-DCM-JP and earlier allows an attacker to execute arbitrary code via unspecified vec | Nov 13, 2017 | 9.8 | 30 | NO | NO |
CVE-2017-10845CRITICAL Wi-Fi STATION L-02F Software version V10g and earlier allows remote attackers to access the device with administrative privileges and perform unintended operations through a backdo | Sep 15, 2017 | 9.8 | 30 | NO | NO |
CVE-2016-4854HIGH Cross-site request forgery (CSRF) vulnerability in L-04D firmware version V10a and V10b allows remote attackers to hijack the authentication of administrators to perform arbitrary | May 22, 2017 | 8.8 | 27 | NO | NO |
CVE-2017-10846HIGH Wi-Fi STATION L-02F Software version V10b and earlier allows remote attackers to bypass access restrictions to obtain information on device settings via unspecified vectors. | Sep 15, 2017 | 7.5 | 23 | NO | NO |
CVE-2017-10812HIGH Untrusted search path vulnerability in Photo Collection PC Software Ver.4.0.2 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. | Aug 29, 2017 | 7.8 | 23 | NO | NO |
CVE-2021-20847MEDIUM Cross-site scripting vulnerability in Wi-Fi STATION SH-52A (38JP_1_11G, 38JP_1_11J, 38JP_1_11K, 38JP_1_11L, 38JP_1_26F, 38JP_1_26G, 38JP_1_26J, 38JP_2_03B, and 38JP_2_03C) allows a | Dec 1, 2021 | 6.1 | 21 | NO | NO |
CVE-2019-5914MEDIUM V20 PRO L-01J software version L01J20c and L01J20d has a NULL pointer exception flaw that can be used by an attacker to cause the device to crash on the same network range via a sp | Feb 13, 2019 | 5.3 | 19 | NO | NO |
CVE-2012-1244MEDIUM The NTT DOCOMO sp mode mail application 5400 and earlier for Android does not properly verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof | Apr 27, 2012 | 5.8 | 19 | NO | NO |
CVE-2014-1979MEDIUM The NTT DOCOMO sp mode mail application 5900 through 6300 for Android 4.0.x and 6000 through 6620 for Android 4.1 through 4.4 allows remote attackers to execute arbitrary Java meth | Mar 19, 2014 | 6.8 | 18 | NO | NO |
CVE-2014-1978MEDIUM The application link interface in the NTT DOCOMO sp mode mail application 6100 through 6300 for Android 4.0.x and 6130 through 6700 for Android 4.1 through 4.4 writes message conte | Mar 19, 2014 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Nttdocomo.
Media articles that mention a CVE ID that affects a product developed by Nttdocomo — matched by CVE ID, not by vendor name.