Vulnerabilities (CVE)

Filtered by vendor Tecno Subscribe
Total 4 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-2190 1 Tecno 1 Com.transsnet.store 2025-06-25 N/A 8.1 HIGH
The mobile application (com.transsnet.store) has a man-in-the-middle attack vulnerability, which may lead to code injection risks.
CVE-2024-3701 1 Tecno 1 Hios 2025-06-17 N/A 9.8 CRITICAL
The system application (com.transsion.kolun.aiservice) component does not perform an authentication check, which allows attackers to perform malicious exploitations and affect system services.
CVE-2025-3698 1 Tecno 1 Carlcare 2025-04-23 N/A 7.5 HIGH
Interface exposure vulnerability in the mobile application (com.transsion.carlcare) may lead to information leakage risk.
CVE-2019-15417 1 Tecno 2 Spark Pro, Spark Pro Firmware 2024-11-21 7.2 HIGH 7.8 HIGH
The Tecno Spark Pro Android device with a build fingerprint of TECNO/H3722/TECNO-K8:7.0/NRD90M/K8-H3722ABCDE-N-171229V96:user/release-keys contains a pre-installed app with a package name of com.lovelyfont.defcontainer app (versionCode=7, versionName=7.0.5) that allows unauthorized dynamic code loading via a confused deputy attack. This capability can be accessed by any app co-located on the device.