CVE-2017-9821: Npci Bharat Interface For Money (bhim)

Critical severity, CVSS 9.8. EPSS: 1.4% chance of exploitation in the next 30 days.

The National Payments Corporation of India BHIM application 1.3 for Android relies on three hardcoded strings (AK-NPCIMB, IM-NPCIBM, and VK-NPCIBM) for SMS validation, which makes it easier for attackers to bypass authentication.

Affected products

  • Npci Bharat Interface For Money (bhim): version 1.3 only

Published 2018-08-24. Last modified 2026-06-17.