High severity7.5NVD Advisory· Published May 11, 2017· Updated May 13, 2026
CVE-2016-10370
CVE-2016-10370
Description
An issue was discovered on OnePlus devices such as the 3T. The OnePlus OTA Updater pushes the signed-OTA image over HTTP without TLS. While it does not allow for installation of arbitrary OTAs (due to the digital signature), it unnecessarily increases the attack surface, and allows for remote exploitation of other vulnerabilities such as CVE-2017-5948, CVE-2017-8850, and CVE-2017-8851.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- alephsecurity.com/vulns/aleph-2017022nvdExploitTechnical DescriptionThird Party Advisory
- forums.oneplus.net/threads/ota-and-imei-over-http.453992/nvdVendor Advisory
- www.securityfocus.com/bid/98495nvd
News mentions
0No linked articles in our index yet.