VYPR
Medium severity6.3NVD Advisory· Published Mar 16, 2026· Updated Jun 17, 2026

CVE-2025-25277

CVE-2025-25277

Description

in OpenHarmony v5.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through using incompatible type. This vulnerability can be exploited only in restricted scenarios.

Affected products

4
  • OpenHarmony/Openharmonycpe-rescue2 versions
    v5.0.3+ 1 more
    • (no CPE)range: v5.0.3
    • (no CPE)range: <=5.1.0
  • cpe:2.3:o:openatom:openharmony:5.0.3:*:*:*:-:*:*:*+ 1 more
    • cpe:2.3:o:openatom:openharmony:5.0.3:*:*:*:-:*:*:*
    • cpe:2.3:o:openatom:openharmony:5.1.0:*:*:*:-:*:*:*

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.