Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 17 Mar 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Openatom
Openatom openharmony |
|
| CPEs | cpe:2.3:o:openatom:openharmony:5.0.3:*:*:*:-:*:*:* cpe:2.3:o:openatom:openharmony:5.1.0:*:*:*:-:*:*:* |
|
| Vendors & Products |
Openatom
Openatom openharmony |
Tue, 17 Mar 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Openharmony
Openharmony openharmony |
|
| Vendors & Products |
Openharmony
Openharmony openharmony |
Mon, 16 Mar 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 16 Mar 2026 07:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | in OpenHarmony v5.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through using incompatible type. This vulnerability can be exploited only in restricted scenarios. | |
| Title | arkcompiler_ets_runtime has a type confusion vulnerability | |
| Weaknesses | CWE-843 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: OpenHarmony
Published:
Updated: 2026-03-16T17:27:12.753Z
Reserved: 2025-03-02T07:20:06.741Z
Link: CVE-2025-25277
Updated: 2026-03-16T17:27:05.806Z
Status : Analyzed
Published: 2026-03-16T14:17:57.090
Modified: 2026-03-17T19:56:01.257
Link: CVE-2025-25277
No data.
OpenCVE Enrichment
Updated: 2026-03-24T10:45:34Z