VYPR

Tinxy

by Tinxy

CVEs (3)

  • CVE-2020-9438MedJun 23, 2020
    risk 0.38cvss 5.9epss 0.01

    Tinxy Door Lock with firmware before 3.2 allow attackers to unlock a door by replaying an Unlock request that occurred when the attacker was previously authorized. In other words, door-access revocation is mishandled.

  • CVE-2024-12094MedDec 5, 2024
    risk 0.35cvss epss 0.00

    This vulnerability exists in the Tinxy mobile app due to storage of logged-in user information in plaintext on the device database. An attacker with physical access to the rooted device could exploit this vulnerability by accessing its database leading to unauthorized access of…

  • CVE-2025-2189MedMar 11, 2025
    risk 0.33cvss epss 0.00

    This vulnerability exists in the Tinxy smart devices due to storage of credentials in plaintext within the device firmware. An attacker with physical access could exploit this by extracting the firmware and analyzing the binary data to obtain the plaintext credentials stored on…