Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Oneplus

First CVE: Jan 23, 2017Active for: 10 yearsTotal CVEs: 15
18.8
VTI Score
Low

OnePlus vulnerabilities concentrate across its OxygenOS mobile operating system and associated flagship devices such as the OnePlus 3T, 3, 2, and One, with the disclosed issues skewing strongly toward critical-severity outcomes. The recurring weakness classes—cleartext transmission of sensitive information, improper privilege and access control, and improper authentication—reflect the authentication, encryption, and permission-enforcement demands of a mobile platform. Live exploitation activity and current exposure counts are shown alongside this summary.

FAUCET AI Generated
15
Total CVEs
More Total CVEs than 94% of tracked vendors
0.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 3% of tracked vendors
7.1
Avg CVSS Score
Higher Avg CVSS Score than 52% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Oneplus over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 23, 2017
9 years ago
Most Recent CVE
Aug 10, 2023
1,080 days ago

Products(12 total)

Top CVEs

Signals from CVEs in this vendor scope (15 CVEs).

15 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2017-5554HIGH
An issue was discovered in ABOOT in OnePlus 3 and 3T OxygenOS before 4.0.2. The attacker can reboot the device into the fastboot mode, which could be done without any authenticatio
Jan 23, 20178.127NONO
CVE-2017-11105CRITICAL
The OnePlus 2 Primary Bootloader (PBL) does not validate the SBL1 partition before executing it, although it contains a certificate. This allows attackers with write access to that
Aug 3, 20179.826NONO
CVE-2017-5626CRITICAL
OxygenOS before version 4.0.2, on OnePlus 3 and 3T, has two hidden fastboot oem commands (4F500301 and 4F500302) that allow the attacker to lock/unlock the bootloader, disregarding
Mar 12, 20179.826NONO
CVE-2023-26309CRITICAL
A remote code execution vulnerability in the webview component of OnePlus Store app.
Aug 10, 20239.825NONO
CVE-2017-5624CRITICAL
An issue was discovered in OxygenOS before 4.0.3 for OnePlus 3 and 3T. The attacker can persistently make the (locked) bootloader start the platform with dm-verity disabled, by iss
Mar 12, 20179.825NONO
CVE-2016-10370HIGH
An issue was discovered on OnePlus devices such as the 3T. The OnePlus OTA Updater pushes the signed-OTA image over HTTP without TLS. While it does not allow for installation of ar
May 11, 20177.522NONO
CVE-2017-5622MEDIUM
With OxygenOS before 4.0.3, when a charger is connected to a powered-off OnePlus 3 or 3T device, the platform starts with adbd enabled. Therefore, a malicious charger or a physical
Mar 26, 20175.922NONO
CVE-2017-8851MEDIUM
An issue was discovered on OnePlus One and X devices. Due to a lenient updater-script on the OnePlus One and X OTA images, the fact that both products use the same OTA verification
May 11, 20175.921NONO
CVE-2017-8850MEDIUM
An issue was discovered on OnePlus One, X, 2, 3, and 3T devices. Due to a lenient updater-script in the OnePlus OTA images, and the fact that both ROMs use the same OTA verificatio
May 11, 20175.921NONO
CVE-2020-7958MEDIUM
An issue was discovered on OnePlus 7 Pro devices before 10.0.3.GM21BA. The firmware was found to contain functionality that allows a privileged user (root) in the Rich Execution En
Apr 14, 20206.018NONO
View all 15 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products15 CVEs
60%
13%
27%
Severity distribution among all CVEs352,427 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (6.7%)
Network9 (60.0%)
Unknown0 (0.0%)
Physical5 (33.3%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (73.3%)
High4 (26.7%)
Unknown0 (0.0%)
User Interaction
None15 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low2 (13.3%)
High1 (6.7%)
None12 (80.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (15 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Oneplus.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Oneplus — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Oneplus's Products

View all 2 CNAs →

Top CWEs