CVE-2020-9438: Medium severity tinxy smart wifi door lock vulnerability
Published Jun 23, 2020
·Updated
Tinxy Door Lock with firmware before 3.2 allow attackers to unlock a door by replaying an Unlock request that occurred when the attacker was previously authorized. In other words, door-access revocation is mishandled.
Affected Software
2 affected components
Tinxy Smart Wifi Door Lock Firmware<3.2
Tinxy Smart Wifi Door Lock
Event History
Jun 23, 2020
CVE Published
via MITRE·02:31 PM
Data Sourced
via MITRE·02:31 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-9438?
CVE-2020-9438 has a medium severity rating due to the vulnerability allowing replay attacks to unlock a door.
2
How do I fix CVE-2020-9438?
To fix CVE-2020-9438, update the firmware of the Tinxy Smart Wifi Door Lock to version 3.2 or later.
3
What devices are affected by CVE-2020-9438?
CVE-2020-9438 affects Tinxy Smart Wifi Door Locks with firmware versions prior to 3.2.
4
What type of vulnerability is CVE-2020-9438?
CVE-2020-9438 is a replay attack vulnerability that improperly handles door-access revocation.
5
What can attackers achieve with CVE-2020-9438?
Attackers can exploit CVE-2020-9438 to unlock a door by replaying a previously authorized unlock request.