tecno 相關的公開 CVE 漏洞與安全風險資訊,提供 CVSS、EPSS、公開時間與漏洞情報資料,協助評估潛在風險與修補優先順序。
| CVE | 摘要 | 來源 | 最高 CVSS | EPSS % | 公開時間 | 更新時間 |
|---|---|---|---|---|---|---|
| CVE-2025-15385 | Insufficient Verification of Data Authenticity vulnerability in TECNO Mobile com.Afmobi.Boomplayer allows Authentication Bypass.This issue affects com.Afmobi.Boomplayer: 7.4.63. | 907edf6c-bf03-423e-ab1a-8da27e1aa1ea | 9.8 | 0.01% | 2026-01-06 | 2026-01-30 |
| CVE-2025-9056 | Unprotected service in the AudioLink component allows a local attacker to overwrite system files via unauthorized service invocation. | 907edf6c-bf03-423e-ab1a-8da27e1aa1ea | 5.3 | 0.03% | 2025-12-10 | 2026-01-02 |
| CVE-2025-3698 | Interface exposure vulnerability in the mobile application (com.transsion.carlcare) may lead to information leakage risk. | 907edf6c-bf03-423e-ab1a-8da27e1aa1ea | 7.5 | 0.34% | 2025-04-16 | 2025-11-13 |
| CVE-2025-2190 | The mobile application (com.transsnet.store) has a man-in-the-middle attack vulnerability, which may lead to code injection risks. | 907edf6c-bf03-423e-ab1a-8da27e1aa1ea | 8.1 | 0.15% | 2025-03-11 | 2025-11-13 |
| CVE-2024-3701 | The system application (com.transsion.kolun.aiservice) component does not perform an authentication check, which allows attackers to perform malicious exploitations and affect system services. | 907edf6c-bf03-423e-ab1a-8da27e1aa1ea | 9.8 | 0.48% | 2024-04-15 | 2025-06-17 |
| CVE-2019-15417 | The Tecno Spark Pro Android device with a build fingerprint of TECNO/H3722/TECNO-K8:7.0/NRD90M/K8-H3722ABCDE-N-171229V96:user/release-keys contains a pre-installed app with a package name of com.lovelyfont.defcontainer app (versionCode=7, versionName=7.0.5) that allows unauthorized dynamic code loading via a confused deputy attack. This capability can be accessed by any app co-located on the device. | [email protected] | 7.8 | 0.14% | 2019-11-14 | 2024-11-21 |