Xolo manufactures a small line of computing and networking devices, including Chromebooks and embedded systems such as the Cube 5.0, where its vulnerability surface centers on firmware and software-update delivery mechanisms. The recurring weakness pattern reflects risks in code-download integrity validation, a structural concern for devices that depend on remote provisioning and update channels. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Xolo over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-15361MEDIUM The Infineon RSA library 1.02.013 in Infineon Trusted Platform Module (TPM) firmware, such as versions before 0000000000000422 - 4.34, before 000000000000062b - 6.43, and before 00 | Oct 16, 2017 | 5.9 | 26 | NO | NO |
CVE-2016-6564HIGH Android devices with code from Ragentek contain a privileged binary that performs over-the-air (OTA) update checks. Additionally, there are multiple techniques used to hide the exe | Jul 13, 2018 | 8.1 | 23 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Xolo.
Media articles that mention a CVE ID that affects a product developed by Xolo — matched by CVE ID, not by vendor name.