5.9
CVE-2025-44612
- EPSS 0.03%
- Veröffentlicht 30.05.2025 00:00:00
- Zuletzt bearbeitet 22.07.2025 14:29:40
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Tinxy WiFi Lock Controller v1 RF was discovered to transmit sensitive information in plaintext, including control information and device credentials, allowing attackers to possibly intercept and access sensitive information via a man-in-the-middle attack.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Tinxy ≫ Wifi Lock Controller V1 Rf Firmware Version-
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.03% | 0.075 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 5.9 | 2.2 | 3.6 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
|
CWE-319 Cleartext Transmission of Sensitive Information
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.