Oklok Project maintains a focused authentication and access-control product where the recurring vulnerability signal centers on session and credential-management weaknesses, including insufficient authentication attempt restrictions, authorization bypass via user-controlled keys, weak password requirements, and inadequate session expiration handling. These patterns reflect the complexity of implementing robust authentication mechanisms and suggest that defenders relying on this product should prioritize configuration hardening and credential-policy enforcement. Current vulnerability counts, severity distribution, and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Oklok Project over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-8790CRITICAL The OKLOK (3.1.1) mobile companion app for Fingerprint Bluetooth Padlock FB50 (2.3) has weak password requirements combined with improper restriction of excessive authentication at | May 4, 2020 | 9.8 | 31 | NO | NO |
CVE-2020-10876HIGH The OKLOK (3.1.1) mobile companion app for Fingerprint Bluetooth Padlock FB50 (2.3) does not correctly implement its timeout on the four-digit verification code that is required fo | May 4, 2020 | 7.5 | 24 | NO | NO |
CVE-2020-8791MEDIUM The OKLOK (3.1.1) mobile companion app for Fingerprint Bluetooth Padlock FB50 (2.3) allows remote attackers to submit API requests using authenticated but unauthorized tokens, resu | May 4, 2020 | 6.5 | 22 | NO | NO |
CVE-2020-8792MEDIUM The OKLOK (3.1.1) mobile companion app for Fingerprint Bluetooth Padlock FB50 (2.3) has an information-exposure issue. In the mobile app, an attempt to add an already-bound lock by | May 4, 2020 | 5.3 | 20 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Oklok Project.
Media articles that mention a CVE ID that affects a product developed by Oklok Project — matched by CVE ID, not by vendor name.