CVE-2025-44619: Critical severity Tinxy WiFi Lock Controller vulnerability
Tinxy WiFi Lock Controller v1 RF was discovered to be configured to transmit on an open Wi-Fi network, allowing attackers to join the network without authentication.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
For Tinxy WiFi Lock Controller v1 RF, configure the device to use a secured Wi‑Fi network with authentication (not an open network) so attackers cannot join without credentials.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-44619?
CVE-2025-44619 has a medium severity rating due to its potential for unauthorized access.
How do I fix CVE-2025-44619?
To fix CVE-2025-44619, configure the Tinxy WiFi Lock Controller to operate on a secure, password-protected network.
What vulnerabilities does CVE-2025-44619 expose?
CVE-2025-44619 exposes the Tinxy WiFi Lock Controller to unauthorized access and control from malicious actors.
Who is affected by CVE-2025-44619?
Users of the Tinxy WiFi Lock Controller version 1 are affected by CVE-2025-44619.
Is there a workaround for CVE-2025-44619?
Yes, a workaround for CVE-2025-44619 is to change the Wi-Fi settings to ensure the device does not connect to open networks.