A logic vulnerability in the the mobile application (com.transsion.applock) can lead to bypassing the application password.
CWE-602 type error means that the password verification mechanism is implemented on the client side (mobile application) rather than on the server side or in a trusted environment. An attacker can exploit this logic flaw to bypass password verification without knowing it. This results in a lack of real protection for applications locked by AppLock.
An attacker with physical access to the device or with appropriate permissions can gain unauthorized access to applications protected by AppLock, bypassing password protection. This can lead to violation of confidentiality, integrity, and availability of data stored in these applications.
Apply patches available from the manufacturer according to the references: https://security.tecno.com/SRC/securityUpdates
Mobile application com.transsion.applock — versions indicated in the manufacturer's references
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H