CVE-2017-5947: Oneplus Oxygenos

Medium severity, CVSS 6.8. EPSS: 0.3% chance of exploitation in the next 30 days.

An issue was discovered in OnePlus One, X, 2, 3, 3T, and 5 devices with OxygenOS 5.0 and earlier. The attacker can reboot the device into the Qualcomm Emergency Download (EDL) mode through ADB or by using Volume-Up when connected to USB, which in turn could allow for downgrading partitions such as the Android Bootloader.

Affected products

  • Oneplus Oxygenos: up to and including 5.0

Published 2018-03-29. Last modified 2026-06-17.