TECNO records
11 published records for vendor tecno.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-732 Incorrect Permission Assignment for Critical Resource3
- CWE-297 Improper Validation of Certificate with Host Mismatch1
- CWE-306 Missing Authentication for Critical Function1
- CWE-345 Insufficient Verification of Data Authenticity1
- CWE-359 Exposure of Private Personal Information to an Unauthorized Actor1
- CWE-749 Exposed Dangerous Method or Function1
The weakness classes this vendor ships most often: where to look.
CWEAll records
11 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2024-3701No exploit | Improper Authentication in com.transsion.kolun.aiservicetecno · hios · CWE-306 | Critical9.8 | — | 0.6% | Apr 15, 2024 |
39Monitor | CVE-2024-5163No exploit | Improper permission settings in com.transsion.carlcaretecno · com.transsion.carlcare · CWE-732 | Critical9.8 | — | 0.5% | Jun 16, 2024 |
39Monitor | CVE-2024-10018No exploit | Improper permission control in the mobile application (com.transsion.aivoiceassistant) can lead to the launch of any unexported component.tecno · com.transsion.aivoiceassistant · CWE-732 | Critical9.8 | — | 0.5% | Oct 15, 2024 |
39Monitor | CVE-2024-8039No exploit | Improper permission configurationDomain configuration vulnerability of the mobile application (com.afmobi.boomplayer) can lead to account tatecno · com.afmobi.boomplayer · CWE-732 | Critical9.8 | — | 0.4% | Sep 14, 2024 |
39Monitor | CVE-2025-15385No exploit | Insufficient Verification of Data Authenticity vulnerability in TECNO Mobile com.Afmobi.Boomplayer allows Authentication Bypass.This issue atecno · boomplay · CWE-345 | Critical9.8 | — | 0.2% | Jan 5, 2026 |
32Monitor | CVE-2025-2190No exploit | The mobile application (com.transsnet.store) has a man-in-the-middle attack vulnerability, which may lead to code injection risks.tecno · com.transsnet.store · CWE-297 | High8.1 | — | 0.3% | Mar 11, 2025 |
31Monitor | CVE-2019-15417No exploit | The Tecno Spark Pro Android device with a build fingerprint of TECNO/H3722/TECNO-K8:7.0/NRD90M/K8-H3722ABCDE-N-171229V96:user/release-keys ctecno · spark pro firmware | High7.8 | — | 0.3% | Nov 14, 2019 |
30Monitor | CVE-2024-4988No exploit | Improper permission control in com.transsion.videocallenhancertecno · com.transsion.videocallenhancer · CWE-269 | High7.5 | — | 0.4% | May 21, 2024 |
30Monitor | CVE-2025-3698No exploit | Interface exposure vulnerability in the mobile application (com.transsion.carlcare) may lead to information leakage risk.tecno · carlcare · CWE-749 | High7.5 | — | 0.4% | Apr 15, 2025 |
30Monitor | CVE-2024-11206No exploit | Unauthorized access vulnerability in the mobile application (com.transsion.phoenix) can lead to the leakage of user information.tecno · com.transsion.phoenix · CWE-359 | High7.5 | — | 0.4% | Nov 14, 2024 |
21Monitor | CVE-2025-9056No exploit | Unprotected service in the AudioLink component allows a local attacker to overwrite system files via unauthorized service invocation.tecno · audiolink · CWE-863 | Medium5.3 | — | 0.2% | Dec 10, 2025 |
- CVE-2024-370139Monitor
Improper Authentication in com.transsion.kolun.aiservice
CriticalCVSS 9.8No exploitEPSS 1%tecno · hiosApr 15, 2024
- CVE-2024-516339Monitor
Improper permission settings in com.transsion.carlcare
CriticalCVSS 9.8No exploitEPSS 1%tecno · com.transsion.carlcareJun 16, 2024
- CVE-2024-1001839Monitor
Improper permission control in the mobile application (com.transsion.aivoiceassistant) can lead to the launch of any unexported component.
CriticalCVSS 9.8No exploitEPSS 1%tecno · com.transsion.aivoiceassistantOct 15, 2024
- CVE-2024-803939Monitor
Improper permission configurationDomain configuration vulnerability of the mobile application (com.afmobi.boomplayer) can lead to account ta
CriticalCVSS 9.8No exploitEPSS 0%tecno · com.afmobi.boomplayerSep 14, 2024
- CVE-2025-1538539Monitor
Insufficient Verification of Data Authenticity vulnerability in TECNO Mobile com.Afmobi.Boomplayer allows Authentication Bypass.This issue a
CriticalCVSS 9.8No exploitEPSS 0%tecno · boomplayJan 5, 2026
- CVE-2025-219032Monitor
The mobile application (com.transsnet.store) has a man-in-the-middle attack vulnerability, which may lead to code injection risks.
HighCVSS 8.1No exploitEPSS 0%tecno · com.transsnet.storeMar 11, 2025
- CVE-2019-1541731Monitor
The Tecno Spark Pro Android device with a build fingerprint of TECNO/H3722/TECNO-K8:7.0/NRD90M/K8-H3722ABCDE-N-171229V96:user/release-keys c
HighCVSS 7.8No exploitEPSS 0%tecno · spark pro firmwareNov 14, 2019
- CVE-2024-498830Monitor
Improper permission control in com.transsion.videocallenhancer
HighCVSS 7.5No exploitEPSS 0%tecno · com.transsion.videocallenhancerMay 21, 2024
- CVE-2025-369830Monitor
Interface exposure vulnerability in the mobile application (com.transsion.carlcare) may lead to information leakage risk.
HighCVSS 7.5No exploitEPSS 0%tecno · carlcareApr 15, 2025
- CVE-2024-1120630Monitor
Unauthorized access vulnerability in the mobile application (com.transsion.phoenix) can lead to the leakage of user information.
HighCVSS 7.5No exploitEPSS 0%tecno · com.transsion.phoenixNov 14, 2024
- CVE-2025-905621Monitor
Unprotected service in the AudioLink component allows a local attacker to overwrite system files via unauthorized service invocation.
MediumCVSS 5.3No exploitEPSS 0%tecno · audiolinkDec 10, 2025