Transsion is a mobile device manufacturer whose disclosed vulnerabilities cluster around its customer service platform (CarlCare), device firmware update mechanism (HIOS), and consumer smartphone products such as the Tecno Pova6 Pro 5G. The recurring exposure centers on information-disclosure and authorization-control weaknesses, reflecting the access-sensitive nature of device management and customer account systems. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Transsion over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-14817MEDIUM The component com.transsion.tranfacmode.entrance.main.MainActivity in com.transsion.tranfacmode has no permission control and can be accessed by third-party apps which can construc | Dec 17, 2025 | 6.5 | 22 | NO | NO |
CVE-2024-7697HIGH Logical vulnerability in the mobile application (com.transsion.carlcare) may lead to user information leakage risks. | Aug 12, 2024 | 7.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Transsion.
Media articles that mention a CVE ID that affects a product developed by Transsion — matched by CVE ID, not by vendor name.