O.Bike operates a stationless bike-sharing platform with associated smart-lock and firmware components, presenting a narrowly scoped but operationally distributed attack surface centered on mobile and IoT device management. The observed vulnerability signal reflects authentication weaknesses, particularly capture-replay vulnerabilities that recur across the bike-sharing and smart-locker product line, a class of flaw endemic to wireless and mobile credential exchange. Current CVE counts, severity, and any confirmed exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by O.Bike over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-16242MEDIUM oBike relies on Hangzhou Luoping Smart Locker to lock bicycles, which allows attackers to bypass the locking mechanism by using Bluetooth Low Energy (BLE) to replay ciphertext base | Sep 14, 2018 | 5.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by O.Bike.
Media articles that mention a CVE ID that affects a product developed by O.Bike — matched by CVE ID, not by vendor name.