PatchSiren cyber security CVE debrief
CVE-2017-5554 Oneplus CVE debrief
CVE-2017-5554 is a OnePlus ABOOT issue in OxygenOS on OnePlus 3 and 3T devices before 4.0.2. If an attacker can get the device into fastboot mode—either physically during boot or through ADB access—they can issue a fastboot command that switches SELinux into permissive mode, significantly reducing Android security controls.
- Vendor
- Oneplus
- Product
- Unknown
- CVSS
- HIGH 8.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-01-23
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-01-23
- Advisory updated
- 2026-05-13
Who should care
OnePlus 3 and 3T owners, mobile device administrators, enterprise mobility teams, and anyone responsible for securing devices that may be physically accessible or exposed to ADB access.
Technical summary
The vulnerability is tied to bootloader/fastboot handling in ABOOT. The published description says an attacker can reboot the device into fastboot without authentication, using either the physical Volume Up boot path or the adb reboot bootloader command when ADB is available. Once in fastboot, the attacker can run fastboot oem selinux permissive, which places the platform SELinux policy into permissive mode and weakens the system’s security enforcement. NVD maps the issue to CWE-287 and lists affected OxygenOS ranges ending at 3.2.8 and 3.5.4 for the referenced device families.
Defensive priority
High for any environment where OnePlus 3/3T devices may still run vulnerable OxygenOS builds and where physical access or ADB exposure is possible.
Recommended defensive actions
- Upgrade OnePlus 3/3T devices to OxygenOS 4.0.2 or later, as identified in the vulnerability description.
- Restrict or disable ADB access on production devices and treat any enabled developer access as sensitive.
- Apply physical security controls to prevent unauthorized access during boot and to prevent unattended device handling.
- Verify device policy settings after updates to ensure SELinux remains enforcing.
- Inventory OnePlus 3 and 3T devices and prioritize remediation for any units running OxygenOS versions at or below the affected ranges.
Evidence notes
The issue description states that an unauthenticated reboot into fastboot is possible through physical boot interaction or via ADB, and that fastboot oem selinux permissive can then weaken SELinux. The NVD record identifies the affected software as OnePlus OxygenOS through version 3.2.8 and 3.5.4, and cites CWE-287. The CVSS 3.0 vector in NVD is AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H, though the narrative attack paths described in the source require local/physical or ADB access.
Sources and references
Verified primary and authoritative sources
-
CVE-2017-5554 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2017-5554
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2017-5554 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2017-5554
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://securityresear.ch/2017/01/11/fastboot-oem-selinux-permissive/
[email protected] - Third Party Advisory
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://www.xda-developers.com/oneplus-33t-bootloader-vulnerability-allows-changing-of-selinux-to-permissive-mode-in-fastboot/
[email protected] - Third Party Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.