Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
OPPO

OPPO Vendor Cyber Rating & Cyber Score

oppo.com

Founded in 2004, OPPO is one of the world's leading innovators of smart devices. With operations in over 70 countries and regions, OPPO's more than 290,000 points of sales and 1,900 official service centers share the beauty of technology with users all over the world. To forward our vision of a better future, OPPO has established ten smart manufacturing facilities around the world, as well as a global design center in London. Every day, our 40,000 employees put their heart and soul into exploring the possibilities of humanistic technology. OPPO is not just a device maker. We are a technology company that combines hardware with software and services. Our software range, built around the ColorOS operating system, makes devices more


OPPO A.I CyberSecurity Scoring

OPPO
Company Information
Website:http://www.oppo.com/en
Employees number:55,786
Number of followers:665,979
NAICS:517
Industry Type:Telecommunications
Homepage:oppo.com
OPPO Risk Score (AI oriented)
Between 800 and 849
logo
OPPOTelecommunications
Updated:
11/08/2026
801/1000
Good
A
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
OPPO Global Score (TPRM)
xxxx
logo
OPPOTelecommunications
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

OPPO
OPPOGood
Current Score
801A (GOOD)
01000
2 incidents
-1 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
798Before Incident
JULY 2026
800Before Incident
JUNE 2026
800Before Incident
MAY 2026
801Before Incident
Vulnerability
01 May 2026OPPO
Quectel and Semtech: Malicious SIMs can shut down phones, steal files, and drag 5G back to 2G

Malicious SIM Cards Exploit Proactive Functionality to Hijack Devices

800After Incident
CRITICAL-1
SEMQUE1786444258
Malicious SIM Cards Exploit Proactive Functionality to Hijack Devices Researchers from the University of Birmingham and Fuzzware have uncovered critical vulnerabilities in how SIM cards interact with smartphones and IoT devices, enabling attackers to execute code, steal data, or force devices onto insecure 2G networks. The findings, presented at the USENIX WOOT conference in Baltimore, highlight risks in proactive SIM functionality a feature designed to let SIMs issue commands to their host devices. Using a toolkit called CATANA, the team led by Tomasz Piotr Lisowski, Marius Muench, and Kristian Covic tested 26 devices (18 smartphones and 8 IoT modems). Nine devices exposed an AT command interface to the SIM, with IoT modems being particularly vulnerable (seven of eight tested). The attacks exploited RUN AT, a command that allows SIMs to execute legacy AT instructions, originally designed for modems in the 1980s. Key vulnerabilities demonstrated include: - Code execution on an Autel EV charger via a Quectel EC25-AFX modem. - Denial-of-service attacks, including forcing an Oppo Reno14 F 5G to power down or lock onto 2G (a downgrade resistant to standard fixes like airplane mode). - File theft from a Quectel EG25-G modem by combining malicious symbolic links with SIM commands. - Unauthorized browser launches on vulnerable Android versions (CVE-2025-48618), patched in December 2025 for Android 13–16. The attacks require SIM control, achievable through compromised software, physical tampering, or supply chain manipulation. While modern smartphones have reduced exposure, IoT devices remain at higher risk. The researchers disclosed findings to Google, Oppo, Quectel, Semtech, Qualcomm, and the GSMA. Qualcomm now disables the SIM AT interface by default, and the GSMA tracks the issue as CVD-2026-0122. The team advocates retiring RUN AT and other high-risk proactive SIM features to mitigate long-term threats.
INCIDENT DETAILS -
TYPE
Vulnerability Exploitation
IMPACT
Data Compromised: File theft, unauthorized data accessSystems Affected: Smartphones, IoT modems, EV chargersDowntime: Denial-of-service (device power down, 2G network lock)Operational Impact: Device hijacking, network downgrade, unauthorized browser launchesIdentity Theft Risk: Potential (if PII was accessed)
DATA BREACH
Type Of Data Compromised: Files, device control dataSensitivity Of Data: Potentially high (if PII or system files were accessed)Data Exfiltration: Yes (file theft demonstrated)Personally Identifiable Information: Potential (not confirmed)
APRIL 2026
800Before Incident
MARCH 2026
800Before Incident
FEBRUARY 2026
800Before Incident
JANUARY 2026
800Before Incident
DECEMBER 2025
800Before Incident
NOVEMBER 2025
799Before Incident
OCTOBER 2025
799Before Incident
SEPTEMBER 2025
799Before Incident
JUNE 2025
801Before Incident
Vulnerability
16 Jun 2025OPPO
OPPO

OPPO Clone Phone Vulnerability Exposes Sensitive User Data

799After Incident
LOW-2
OPP603062425
A critical security vulnerability has been discovered in OPPO’s Clone Phone feature that could expose sensitive user data through inadequately secured WiFi hotspots. The vulnerability, designated CVE-2025-27387, affects ColorOS 15.0.2 and earlier versions, presenting a high-severity risk. The flaw allows nearby attackers to intercept personal data like contacts, messages, and photos without requiring special access, putting millions of OPPO device users at risk of data exposure. The vulnerability stems from weak WPA passphrase protection on WiFi hotspots used for file transfers.
INCIDENT DETAILS -
TYPE
Vulnerability Exploitation
MOTIVATION
Unauthorized information disclosure
IMPACT
contactsmessagesphotosapplication dataColorOS 15.0.2 and earlier versions
DATA BREACH
contactsmessagesphotosapplication dataSensitivity Of Data: HighData Encryption: Weakcontactsmessagesphotosapplication data

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for OPPO ?
?
What was OPPO's A.I Rankiteo Cyber Score in July 2026 ?
?
What was OPPO's A.I Rankiteo Cyber Score in June 2026 ?
?
What was OPPO's A.I Rankiteo Cyber Score in May 2026 ?
?
What was OPPO's A.I Rankiteo Cyber Score in April 2026 ?
?
What was OPPO's A.I Rankiteo Cyber Score in March 2026 ?
?
What was OPPO's A.I Rankiteo Cyber Score in February 2026 ?
?
What was OPPO's A.I Rankiteo Cyber Score in January 2026 ?
?
What was OPPO's A.I Rankiteo Cyber Score in December 2025 ?
?
What was OPPO's A.I Rankiteo Cyber Score in November 2025 ?
?
What was OPPO's A.I Rankiteo Cyber Score in October 2025 ?
?
What was OPPO's A.I Rankiteo Cyber Score in September 2025 ?
?
What is the average per-incident point impact on OPPO's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with OPPO ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view OPPO's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?