CVE-2025-1298 Details
Description
Logic vulnerability in the mobile application (com.transsion.carlcare) may lead to the risk of account takeover.
A logic vulnerability has been identified in the TECNO Carlcare mobile application, version 6.2.8.1, which may lead to account takeover. This vulnerability arises from a flaw in the application's logic, creating a potential risk for users' accounts to be compromised.
The vulnerability has been fixed in the latest security patch. Users can update their application to the latest version to address this issue.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Feb 14, 2025CISA-ADP
Assessed Feb 18, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://security.tecno.com/SRC/blogdetail/383?lang=en_US | TECNOMobile | AdvisoryRemedyVendor |
| https://security.tecno.com/SRC/securityUpdates | TECNOMobile | Vendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-290 | Authentication Bypass by Spoofing | TECNOMobile |
Affected Products
| Product | Versions |
|---|---|
| com.transsion.carlcare | All versions |
CPE
Remediation
| |
| TECNO POVA 5 | All versions |
CPE
Remediation
| |
| TECNO POVA 5 Pro 5G | All versions |
CPE
Remediation
| |
| TECNO POVA 6 Neo 5G | All versions |
CPE
Remediation
| |
| TECNO POP 7 | All versions |
CPE
Remediation
| |
| TECNO POP 8 | All versions |
CPE
Remediation
| |
| TECNO SPARK 10C | All versions |
CPE
Remediation
| |
| TECNO SPARK 10 Pro | All versions |
CPE
Remediation
| |
| TECNO SPARK 20 | All versions |
CPE
Remediation
| |
| TECNO SPARK 20 Pro | All versions |
CPE
Remediation
| |
| TECNO SPARK 20 Pro 5G | All versions |
CPE
Remediation
| |
| TECNO SPARK 20C | All versions |
CPE
Remediation
| |
| TECNO SPARK 30C | All versions |
CPE
Remediation
| |
| TECNO SPARK 30C 5G | All versions |
CPE
Remediation
| |
| TECNO SPARK Go 1S | All versions |
CPE
Remediation
| |
| TECNO SPARK Go 2024 | All versions |
CPE
Remediation
| |
| TECNO CAMON 20 Pro 5G | All versions |
CPE
Remediation
| |
| TECNO CAMON 30 | All versions |
CPE
Remediation
| |
| TECNO CAMON 30S Pro | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | TECNOMobile |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Sep 5, 2025 | CVE Modified | TECNOMobile |
| Feb 18, 2025 | CVE Modified | CISA-ADP |
| Feb 14, 2025 | New CVE Received | TECNOMobile |
Volerion