Vivo Mobile Communication Co., Ltd. produces a range of smartphone devices and associated firmware, with vulnerabilities recurring across its V7 product line, app store, and system services such as frame and touch modules. The exposure centers on authentication gaps, sensitive-information handling, and resource-access control issues characteristic of mobile device software stacks, where misconfigurations in critical functions and logging practices can expose user data or system resources to unauthorized actors. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Vivo Mobile Communication Co., Ltd. over time
Of all the CVEs published by Vivo Mobile Communication Co., Ltd. as a CNA, 30.4% affect products that Vivo Mobile Communication Co., Ltd. develops as a vendor.
Of all the CVEs published that affect products developed by Vivo Mobile Communication Co., Ltd., 63.6% are self-published by Vivo Mobile Communication Co., Ltd. as a CNA.
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-26277CRITICAL The framework service handles pendingIntent incorrectly, allowing a malicious application with certain privileges to perform privileged actions. | Feb 17, 2023 | 9.8 | 29 | NO | NO |
CVE-2017-17463HIGH Vivo modems allow remote attackers to obtain sensitive information by reading the index.cgi?page=wifi HTML source code, as demonstrated by ssid and psk_wepkey fields. | Dec 8, 2017 | 7.5 | 24 | NO | NO |
CVE-2018-15000MEDIUM The Vivo V7 Android device with a build fingerprint of vivo/1718/1718:7.1.2/N2G47H/compil11021857:user/release-keys contains a platform app with a package name of com.vivo.smartsho | Apr 25, 2019 | 6.3 | 21 | NO | NO |
CVE-2025-15515MEDIUM The authentication mechanism for a specific feature in the EasyShare module contains a vulnerability. If specific conditions are met on a local network, it can cause data leakage | Mar 13, 2026 | 5.5 | 20 | NO | NO |
CVE-2025-15509MEDIUM The SmartRemote module has insufficient restrictions on loading URLs, which may lead to some information leakage. | Feb 27, 2026 | 4.3 | 19 | NO | NO |
CVE-2018-15001MEDIUM The Vivo V7 Android device with a build fingerprint of vivo/1718/1718:7.1.2/N2G47H/compil11021857:user/release-keys contains a platform app with a package name of com.vivo.bsptest | Dec 28, 2018 | 5.5 | 19 | NO | NO |
CVE-2018-15002MEDIUM The Vivo V7 device with a build fingerprint of vivo/1718/1718:7.1.2/N2G47H/compil11021857:user/release-keys allows any app co-located on the device to set system properties as the | Dec 28, 2018 | 4.7 | 18 | NO | NO |
Insufficient protection mechanisms in the Health Module may lead to partial information disclosure. | Feb 27, 2026 | 3.3 | 17 | NO | NO |
CVE-2020-12488MEDIUM The attacker can access the sensitive information stored within the jovi Smart Scene module by entering carefully constructed commands without requesting permission. | Nov 10, 2021 | 5.5 | 17 | NO | NO |
CVE-2020-12483MEDIUM The appstore before 8.12.0.0 exposes some of its components, and the attacker can cause remote download and install apps through carefully constructed parameters. | Mar 23, 2021 | 6.1 | 17 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Vivo Mobile Communication Co., Ltd..
Media articles that mention a CVE ID that affects a product developed by Vivo Mobile Communication Co., Ltd. — matched by CVE ID, not by vendor name.