Tinxy's vulnerability profile is concentrated in Wi-Fi-enabled smart-lock products, including its WiFi Lock Controller and Smart WiFi Door Lock lines and their firmware components. The recurring exposure centers on authentication and credential-handling weaknesses, including capture-replay vulnerabilities, cleartext storage and transmission of sensitive information, and improper access control—issues characteristic of IoT device implementations where secure credential management and encrypted communications are critical to preventing unauthorized entry.
The number and severity of CVEs published that impact products developed by Tinxy over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-44619CRITICAL Tinxy WiFi Lock Controller v1 RF was discovered to be configured to transmit on an open Wi-Fi network, allowing attackers to join the network without authentication. | May 30, 2025 | 9.1 | 30 | NO | NO |
CVE-2025-44614HIGH Tinxy WiFi Lock Controller v1 RF was discovered to store users' sensitive information, including credentials and mobile phone numbers, in plaintext. | May 30, 2025 | 7.5 | 21 | NO | NO |
CVE-2020-9438MEDIUM Tinxy Door Lock with firmware before 3.2 allow attackers to unlock a door by replaying an Unlock request that occurred when the attacker was previously authorized. In other words, | Jun 23, 2020 | 5.9 | 21 | NO | NO |
CVE-2025-44612MEDIUM Tinxy WiFi Lock Controller v1 RF was discovered to transmit sensitive information in plaintext, including control information and device credentials, allowing attackers to possibly | May 30, 2025 | 5.9 | 17 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tinxy.
Media articles that mention a CVE ID that affects a product developed by Tinxy — matched by CVE ID, not by vendor name.