Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

ZenHive — Vulnerabilities & Security Advisories 13

Browse all 13 CVE security advisories affecting ZenHive. AI-powered Chinese analysis, POCs, and references for each vulnerability.

This page aggregates security advisories and vulnerability reports for the vendor ZenHive, focusing on known weaknesses in their hardware and software products. It collects data regarding buffer overflow issues, authentication flaws, and access control defects across their device lineup, covering reports published between 2022 and the present. Visitors can track the frequency of new advisories, analyze the prevalence of specific weakness classes, and review the complete vulnerability history for individual ZenHive product lines. The dataset is organized by release date and product category, allowing analysts to identify patterns in remediation timelines and correlate multiple CVE entries into coherent vulnerability trends. This structured view supports security teams in prioritizing patches and understanding the long-term security posture of ZenHive’s ecosystem without needing to manually parse scattered press releases or vendor bulletins.

Top products by ZenHive: mpp
CVE ID Title CVSS Severity Published
CVE-2026-87119 mpp Tempo subscription key authorization is not bound to the issuing challenge, allowing a captured activation credential to be replayed — mpp CWE-294 8.2 High 2026-09-22
CVE-2026-89420 Session voucher adding no new funds is accepted without a charge in mpp, serving paid resources for free — mpp CWE-1284 7.1 High 2026-09-22
CVE-2026-88255 mpp Tempo keys its pre-broadcast dedup reserve on the caller-supplied transaction encoding, so a re-encoded signed transaction reserves a second slot — mpp CWE-1289 6.3 Medium 2026-09-16
CVE-2026-89186 mpp writes Payment-Receipt and Cache-Control before the wrapped application runs, letting a consumer's own Cache-Control expose paid responses to shared caches — mpp CWE-524 6.3 Medium 2026-09-16
CVE-2026-82750 Unbounded EIP-7702 authorization list in mpp Tempo fee-payer sponsorship inflates gas cost and sponsors account delegation — mpp CWE-1284 8.3 High 2026-09-06
CVE-2026-82751 Unbounded key authorization in mpp Tempo fee-payer sponsorship inflates gas cost and sponsors access-key provisioning — mpp CWE-1284 8.3 High 2026-09-06
CVE-2026-67581 On-chain transfer proof is not single-use in mpp EVM payment method, enabling cross-challenge replay — mpp CWE-294 8.7 High 2026-08-19
CVE-2026-73541 Tempo fee sponsorship in mpp bounds each transaction but not aggregate exposure, allowing concurrent sponsor-wallet drain — mpp CWE-770 8.3 High 2026-08-19
CVE-2026-73136 Static memo configuration in mpp Tempo disables per-challenge attribution binding, enabling third-party replay — mpp CWE-294 8.2 High 2026-08-19
CVE-2026-73829 Non-atomic hash-credential dedup in mpp Tempo allows replay of a confirmed payment under a concurrent race — mpp CWE-367 6.3 Medium 2026-08-19
CVE-2026-59252 Missing gas_limit validation in mpp Tempo fee-payer enables wallet drain — mpp CWE-1284 - - 2026-07-17
CVE-2026-59694 Unbounded access list in mpp Tempo fee-payer inflates gas cost per payment — mpp CWE-1284 - - 2026-07-17
CVE-2026-59695 Unbounded max_fee_per_gas in mpp Tempo fee-payer enables single-request wallet drain — mpp CWE-1284 - - 2026-07-17

This page lists every published CVE security advisory associated with ZenHive. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.