CVE-2017-5625: Oneplus Oxygenos

Medium severity, CVSS 4.6. EPSS: 0.3% chance of exploitation in the next 30 days.

In OxygenOS before 4.0.3 on OnePlus 3 and 3T devices, an unauthorized attacker can cause a locked bootloader to partially dump the ciphertext content of an arbitrary partition (except 'keystore') by issuing the 'fastboot oem dump <partition>' fastboot command.

Affected products

  • Oneplus Oxygenos: up to and including 4.0.2

Published 2017-04-25. Last modified 2026-06-17.