Cht maintains a focused web-application product, Tender Doc Transfer, where the durable signal centers on application-layer input and request-handling vulnerabilities including cross-site scripting, cross-site request forgery, and path-traversal issues. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cht over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-13282HIGH TenderDocTransfer developed by Chunghwa Telecom has a Arbitrary File Delete vulnerability. The application sets up a simple local web server and provides APIs for communication wit | Nov 17, 2025 | 8.1 | 28 | NO | NO |
CVE-2024-12641CRITICAL TenderDocTransfer from Chunghwa Telecom has a Reflected Cross-site scripting vulnerability. The application sets up a simple local web server and provides APIs for communication wi | Dec 16, 2024 | 9.6 | 28 | NO | NO |
CVE-2025-13283HIGH TenderDocTransfer developed by Chunghwa Telecom has a Arbitrary File Copy and Paste vulnerability. The application sets up a simple local web server and provides APIs for communic | Nov 17, 2025 | 7.1 | 25 | NO | NO |
CVE-2024-12642HIGH TenderDocTransfer from Chunghwa Telecom has an Arbitrary File Write vulnerability. The application sets up a simple local web server and provides APIs for communication with the ta | Dec 16, 2024 | 8.1 | 23 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cht.
Media articles that mention a CVE ID that affects a product developed by Cht — matched by CVE ID, not by vendor name.