CVE-2018-16242: O.bike Obike-Stationless Bike Sharing
Medium severity, CVSS 5.3. EPSS: 0.7% chance of exploitation in the next 30 days.
oBike relies on Hangzhou Luoping Smart Locker to lock bicycles, which allows attackers to bypass the locking mechanism by using Bluetooth Low Energy (BLE) to replay ciphertext based on a predictable nonce used in the locking protocol.
Affected products
- O.bike Obike-Stationless Bike Sharing: version 2.5.4 only
- O.bike Smart Locker Firmware: affected versions not specified
Published 2018-09-14. Last modified 2026-06-17.