CVE-2025-44614

Tinxy WiFi Lock Controller v1 RF was discovered to store users' sensitive information, including credentials and mobile phone numbers, in plaintext.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:tinxy:wifi_lock_controller_firmware:1:*:*:*:*:*:*:*
cpe:2.3:h:tinxy:wifi_lock_controller:-:*:*:*:*:*:*:*

History

19 Jun 2025, 01:06

Type Values Removed Values Added
CPE cpe:2.3:o:tinxy:wifi_lock_controller_firmware:1:*:*:*:*:*:*:*
cpe:2.3:h:tinxy:wifi_lock_controller:-:*:*:*:*:*:*:*
First Time Tinxy wifi Lock Controller Firmware
Tinxy wifi Lock Controller
Tinxy
References () https://github.com/ShravanSinghRathore/Tinxy/wiki/1.-WiFi-Lock-Controller-v1-RF-%281%E2%80%909%29 - () https://github.com/ShravanSinghRathore/Tinxy/wiki/1.-WiFi-Lock-Controller-v1-RF-%281%E2%80%909%29 - Third Party Advisory

30 May 2025, 22:15

Type Values Removed Values Added
CWE CWE-312
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

30 May 2025, 16:31

Type Values Removed Values Added
Summary
  • (es) Se descubrió que Tinxy WiFi Lock Controller v1 RF almacena información confidencial de los usuarios, incluidas credenciales y números de teléfono móvil, en texto sin formato.

30 May 2025, 03:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-30 03:15

Updated : 2025-06-19 01:06


NVD link : CVE-2025-44614

Mitre link : CVE-2025-44614

CVE.ORG link : CVE-2025-44614


JSON object : View

Products Affected

tinxy

  • wifi_lock_controller_firmware
  • wifi_lock_controller
CWE
CWE-312

Cleartext Storage of Sensitive Information