Tinxy WiFi Lock Controller v1 RF was discovered to transmit sensitive information in plaintext, including control information and device credentials, allowing attackers to possibly intercept and access sensitive information via a man-in-the-middle attack.
History

Thu, 19 Jun 2025 01:30:00 +0000

Type Values Removed Values Added
First Time appeared Tinxy
Tinxy wifi Lock Controller
Tinxy wifi Lock Controller Firmware
CPEs cpe:2.3:h:tinxy:wifi_lock_controller:-:*:*:*:*:*:*:*
cpe:2.3:o:tinxy:wifi_lock_controller_firmware:1:*:*:*:*:*:*:*
Vendors & Products Tinxy
Tinxy wifi Lock Controller
Tinxy wifi Lock Controller Firmware

Fri, 30 May 2025 22:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-319
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 30 May 2025 02:30:00 +0000

Type Values Removed Values Added
Description Tinxy WiFi Lock Controller v1 RF was discovered to transmit sensitive information in plaintext, including control information and device credentials, allowing attackers to possibly intercept and access sensitive information via a man-in-the-middle attack.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2025-05-30T00:00:00.000Z

Updated: 2025-05-30T22:02:19.532Z

Reserved: 2025-04-22T00:00:00.000Z

Link: CVE-2025-44612

cve-icon Vulnrichment

Updated: 2025-05-30T14:41:56.456Z

cve-icon NVD

Status : Analyzed

Published: 2025-05-30T03:15:20.110

Modified: 2025-06-19T01:08:28.777

Link: CVE-2025-44612

cve-icon Redhat

No data.