CVE-2017-9821: Npci Bharat Interface For Money (bhim)
Critical severity, CVSS 9.8. EPSS: 1.4% chance of exploitation in the next 30 days.
The National Payments Corporation of India BHIM application 1.3 for Android relies on three hardcoded strings (AK-NPCIMB, IM-NPCIBM, and VK-NPCIBM) for SMS validation, which makes it easier for attackers to bypass authentication.
Affected products
- Npci Bharat Interface For Money (bhim): version 1.3 only
Published 2018-08-24. Last modified 2026-06-17.