Vivvo
Products
24- 6 CVEs
- 3 CVEs
- 2 CVEs
- 2 CVEs
- 2 CVEs
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
Recent CVEs
26| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-11535 | Cri | 0.61 | — | 0.00 | Jun 12, 2026 | An unauthorized access vulnerability exists in the PcSuite APP. The vulnerability can be exploited by attackers to Unauthorized access to the victim’s device. | ||
| CVE-2020-12483 | Hig | 0.53 | 8.2 | 0.01 | Mar 23, 2021 | The appstore before 8.12.0.0 exposes some of its components, and the attacker can cause remote download and install apps through carefully constructed parameters. | ||
| CVE-2024-13186 | Hig | 0.49 | 7.5 | 0.00 | Jan 8, 2025 | The MinigameCenter module has insufficient restrictions on loading URLs, which may lead to some information leakage. | ||
| CVE-2024-13185 | Hig | 0.49 | 7.5 | 0.00 | Jan 8, 2025 | The MinigameCenter module has insufficient restrictions on loading URLs, which may lead to some information leakage. | ||
| CVE-2024-13173 | Hig | 0.49 | 7.5 | 0.00 | Jan 8, 2025 | The health module has insufficient restrictions on loading URLs, which may lead to some information leakage. | ||
| CVE-2017-17463 | Hig | 0.49 | 7.5 | 0.01 | Dec 8, 2017 | Vivo modems allow remote attackers to obtain sensitive information by reading the index.cgi?page=wifi HTML source code, as demonstrated by ssid and psk_wepkey fields. | ||
| CVE-2020-12487 | Hig | 0.46 | 7.0 | 0.00 | Dec 17, 2024 | Due to the flaws in the verification of input parameters, the attacker can input carefully constructed commands to make the ABE service execute some commands with root privilege. | ||
| CVE-2020-12484 | Med | 0.42 | 6.4 | 0.00 | Dec 17, 2024 | When using special mode to connect to enterprise wifi, certain options are not properly configured and attackers can pretend to be enterprise wifi through a carefully constructed wifi with the same name, which can lead to man-in-the-middle attacks. | ||
| CVE-2021-26278 | Med | 0.41 | 6.3 | 0.00 | Dec 17, 2024 | The wifi module exposes the interface and has improper permission control, leaking sensitive information about the device. | ||
| CVE-2018-15000 | Med | 0.41 | 6.3 | 0.00 | Apr 25, 2019 | The Vivo V7 Android device with a build fingerprint of vivo/1718/1718:7.1.2/N2G47H/compil11021857:user/release-keys contains a platform app with a package name of com.vivo.smartshot (versionCode=1, versionName=3.0.0). This app contains an exported service named… | ||
| CVE-2021-26279 | Med | 0.38 | 5.9 | 0.00 | Dec 17, 2024 | Some parameters of the weather module are improperly stored, leaking some sensitive information. | ||
| CVE-2025-15515 | Med | 0.36 | 5.5 | 0.00 | Mar 13, 2026 | The authentication mechanism for a specific feature in the EasyShare module contains a vulnerability. If specific conditions are met on a local network, it can cause data leakage | ||
| CVE-2021-26277 | Med | 0.36 | 5.6 | 0.00 | Feb 17, 2023 | The framework service handles pendingIntent incorrectly, allowing a malicious application with certain privileges to perform privileged actions. | ||
| CVE-2020-12488 | Med | 0.36 | 5.5 | 0.00 | Nov 10, 2021 | The attacker can access the sensitive information stored within the jovi Smart Scene module by entering carefully constructed commands without requesting permission. | ||
| CVE-2020-12485 | Med | 0.36 | 5.5 | 0.00 | Nov 10, 2020 | The frame touch module does not make validity judgments on parameter lengths when processing specific parameters,which caused out of the boundary when memory access.The vulnerability eventually leads to a local DOS on the device. | ||
| CVE-2018-15001 | Med | 0.36 | 5.5 | 0.00 | Dec 28, 2018 | The Vivo V7 Android device with a build fingerprint of vivo/1718/1718:7.1.2/N2G47H/compil11021857:user/release-keys contains a platform app with a package name of com.vivo.bsptest (versionCode=1, versionName=1.0) containing an exported activity app component named… | ||
| CVE-2026-12058 | Med | 0.34 | — | 0.00 | Jun 12, 2026 | The connection confirmation pop-up of a specific feature in the PcSuite can be bypassed. | ||
| CVE-2025-5719 | Med | 0.33 | — | 0.00 | Jun 6, 2025 | The wallet has an authentication bypass vulnerability that allows access to specific pages. | ||
| CVE-2024-46941 | Med | 0.31 | — | 0.00 | Jun 6, 2025 | SystemUI has an incorrect component protection setting, which allows access to specific information. | ||
| CVE-2018-15002 | Med | 0.31 | 4.7 | 0.00 | Dec 28, 2018 | The Vivo V7 device with a build fingerprint of vivo/1718/1718:7.1.2/N2G47H/compil11021857:user/release-keys allows any app co-located on the device to set system properties as the com.android.phone user. The com.qualcomm.qti.modemtestmode app (versionCode=25, versionName=7.1.2)… |
- risk 0.61cvss —epss 0.00
An unauthorized access vulnerability exists in the PcSuite APP. The vulnerability can be exploited by attackers to Unauthorized access to the victim’s device.
- risk 0.53cvss 8.2epss 0.01
The appstore before 8.12.0.0 exposes some of its components, and the attacker can cause remote download and install apps through carefully constructed parameters.
- risk 0.49cvss 7.5epss 0.00
The MinigameCenter module has insufficient restrictions on loading URLs, which may lead to some information leakage.
- risk 0.49cvss 7.5epss 0.00
The MinigameCenter module has insufficient restrictions on loading URLs, which may lead to some information leakage.
- risk 0.49cvss 7.5epss 0.00
The health module has insufficient restrictions on loading URLs, which may lead to some information leakage.
- risk 0.49cvss 7.5epss 0.01
Vivo modems allow remote attackers to obtain sensitive information by reading the index.cgi?page=wifi HTML source code, as demonstrated by ssid and psk_wepkey fields.
- risk 0.46cvss 7.0epss 0.00
Due to the flaws in the verification of input parameters, the attacker can input carefully constructed commands to make the ABE service execute some commands with root privilege.
- risk 0.42cvss 6.4epss 0.00
When using special mode to connect to enterprise wifi, certain options are not properly configured and attackers can pretend to be enterprise wifi through a carefully constructed wifi with the same name, which can lead to man-in-the-middle attacks.
- risk 0.41cvss 6.3epss 0.00
The wifi module exposes the interface and has improper permission control, leaking sensitive information about the device.
- risk 0.41cvss 6.3epss 0.00
The Vivo V7 Android device with a build fingerprint of vivo/1718/1718:7.1.2/N2G47H/compil11021857:user/release-keys contains a platform app with a package name of com.vivo.smartshot (versionCode=1, versionName=3.0.0). This app contains an exported service named…
- risk 0.38cvss 5.9epss 0.00
Some parameters of the weather module are improperly stored, leaking some sensitive information.
- risk 0.36cvss 5.5epss 0.00
The authentication mechanism for a specific feature in the EasyShare module contains a vulnerability. If specific conditions are met on a local network, it can cause data leakage
- risk 0.36cvss 5.6epss 0.00
The framework service handles pendingIntent incorrectly, allowing a malicious application with certain privileges to perform privileged actions.
- risk 0.36cvss 5.5epss 0.00
The attacker can access the sensitive information stored within the jovi Smart Scene module by entering carefully constructed commands without requesting permission.
- risk 0.36cvss 5.5epss 0.00
The frame touch module does not make validity judgments on parameter lengths when processing specific parameters,which caused out of the boundary when memory access.The vulnerability eventually leads to a local DOS on the device.
- risk 0.36cvss 5.5epss 0.00
The Vivo V7 Android device with a build fingerprint of vivo/1718/1718:7.1.2/N2G47H/compil11021857:user/release-keys contains a platform app with a package name of com.vivo.bsptest (versionCode=1, versionName=1.0) containing an exported activity app component named…
- risk 0.34cvss —epss 0.00
The connection confirmation pop-up of a specific feature in the PcSuite can be bypassed.
- risk 0.33cvss —epss 0.00
The wallet has an authentication bypass vulnerability that allows access to specific pages.
- risk 0.31cvss —epss 0.00
SystemUI has an incorrect component protection setting, which allows access to specific information.
- risk 0.31cvss 4.7epss 0.00
The Vivo V7 device with a build fingerprint of vivo/1718/1718:7.1.2/N2G47H/compil11021857:user/release-keys allows any app co-located on the device to set system properties as the com.android.phone user. The com.qualcomm.qti.modemtestmode app (versionCode=25, versionName=7.1.2)…