CVE-2025-2189 is a medium-severity vulnerability affecting Tinxy smart devices, where credentials are stored in plaintext within the device firmware. An attacker with physical access can extract the firmware and analyze it to retrieve these sensitive credentials. The attack requires physical access, has low complexity, and could lead to high confidentiality impact. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Mogify Infotech | Tinxy 1 Node 10A And 16A Smart Wi-Fi Switches | all versionsCNA affecteddefault unaffected | |
| Mogify Infotech | Tinxy 2, 4 And 6 Node Smart Wi-Fi Switches | all versionsCNA affecteddefault unaffected | |
| Mogify Infotech | Tinxy Door Lock With Wi-Fi Controller | all versionsCNA affecteddefault unaffected | |
| Mogify Infotech | Tinxy Smart 15 Watts 3 In 1 Square Panel Ceiling Light | all versionsCNA affecteddefault unaffected | |
| Mogify Infotech | Tinxy Smart 8 Watts 3 In 1 Round Panel Ceiling Light | all versionsCNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.