CVE-2025-44612: Medium severity tinxy wifi lock controller vulnerability
Published May 30, 2025
·Updated
Tinxy WiFi Lock Controller v1 RF was discovered to transmit sensitive information in plaintext, including control information and device credentials, allowing attackers to possibly intercept and access sensitive information via a man-in-the-middle attack.
Affected Software
3 affected components
Tinxy WiFi Lock Controller
All of the following
Tinxy Wifi Lock Controller V1 Rf Firmware
Tinxy WiFi Lock Controller v1 RF
Event History
May 30, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-44612?
CVE-2025-44612 is considered a high severity vulnerability due to the potential for sensitive information theft.
2
How do I fix CVE-2025-44612?
To fix CVE-2025-44612, ensure that firmware is updated to a version that encrypts transmitted data.
3
What type of attack is possible due to CVE-2025-44612?
CVE-2025-44612 is vulnerable to man-in-the-middle attacks that could expose sensitive information.
4
What sensitive information is at risk with CVE-2025-44612?
CVE-2025-44612 transmits sensitive control information and device credentials in plaintext.
5
Which product is affected by CVE-2025-44612?
CVE-2025-44612 affects the Tinxy WiFi Lock Controller v1 RF.