CVE-2025-44612
Last modified
CVE-2025-44612 is a medium-severity vulnerability rated 5.9/10 on the CVSS scale. Tinxy WiFi Lock Controller v1 RF was discovered to transmit sensitive information in plaintext, including control information and device credentials, allowing attackers to possibly intercept and access sensitive information via a man-in-the-middle attack.. EPSS estimates a 0.17% chance of exploitation in the next 30 days.
Description
Tinxy WiFi Lock Controller v1 RF was discovered to transmit sensitive information in plaintext, including control information and device credentials, allowing attackers to possibly intercept and access sensitive information via a man-in-the-middle attack.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Tinxy | Wifi Lock Controller V1 Rf Firmware | All versions |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-44612?
How severe is CVE-2025-44612?
How do I fix CVE-2025-44612?
Are you affected by CVE-2025-44612?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
