Ttlock provides smart lock access-control and credential-management software serving consumers and building operators; its vulnerability profile centers on the single Ttlock product with recurring weaknesses in authorization enforcement and password-recovery mechanisms. These are foundational access-control issues that deserve attention in any lock or building-management context; current vulnerability counts, severity, and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ttlock over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-12943HIGH TTLock devices do not properly restrict password-reset attempts, leading to incorrect access control and disclosure of sensitive information about valid account names. | Sep 10, 2019 | 8.1 | 25 | NO | NO |
CVE-2019-12942MEDIUM TTLock devices do not properly block guest access in certain situations where the network connection to the cloud is unavailable. | Sep 10, 2019 | 6.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ttlock.
Media articles that mention a CVE ID that affects a product developed by Ttlock — matched by CVE ID, not by vendor name.