PT-2025-23234 · Unknown · Tinxy Wifi Lock Controller

CVE-2025-44614

·

Publicado

2025-05-30

·

Atualizado

2025-07-22

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Tinxy WiFi Lock Controller version v1 RF
Description The issue concerns the storage of sensitive user information, including credentials and mobile phone numbers, in plaintext.
Recommendations For Tinxy WiFi Lock Controller version v1 RF, consider updating the software to a version that securely stores user data, if available. As a temporary workaround, restrict access to the device to minimize the risk of unauthorized data access. Avoid using the device until the issue is resolved or a secure alternative is implemented.

Correção

Cleartext Storage of Sensitive Information

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-44614

Produtos afetados

Tinxy Wifi Lock Controller