CVE-2025-30072

Tiiwee X1 Alarm System TWX1HAKV2 allows Authentication Bypass by Capture-replay, leading to physical Access to the protected facilities without triggering an alarm.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:tiiwee:twx1hakv2_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:tiiwee:twx1hakv2:-:*:*:*:*:*:*:*

History

12 Jun 2025, 16:25

Type Values Removed Values Added
CPE cpe:2.3:o:tiiwee:twx1hakv2_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:tiiwee:twx1hakv2:-:*:*:*:*:*:*:*
First Time Tiiwee twx1hakv2
Tiiwee twx1hakv2 Firmware
Tiiwee
References () https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2025-006.txt - () https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2025-006.txt - Third Party Advisory
References () https://www.tiiwee.com/collections/x1-alarm-systems - () https://www.tiiwee.com/collections/x1-alarm-systems - Product
References () http://seclists.org/fulldisclosure/2025/May/20 - () http://seclists.org/fulldisclosure/2025/May/20 - Mailing List

21 May 2025, 20:25

Type Values Removed Values Added
Summary
  • (es) Tiiwee X1 Alarm System TWX1HAKV2 permite la omisión de la autenticación mediante captura y repetición, lo que permite el acceso físico a las instalaciones protegidas sin activar una alarma.

19 May 2025, 16:15

Type Values Removed Values Added
CWE CWE-294
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.6

19 May 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-19 15:15

Updated : 2025-06-12 16:25


NVD link : CVE-2025-30072

Mitre link : CVE-2025-30072

CVE.ORG link : CVE-2025-30072


JSON object : View

Products Affected

tiiwee

  • twx1hakv2
  • twx1hakv2_firmware
CWE
CWE-294

Authentication Bypass by Capture-replay