CVE-2025-2189 - CVE House
Back to Database
Status published Medium CVE-2025-2189

Information Disclosure Vulnerability in Tinxy Smart Devices

Vulnerability Description

This vulnerability exists in the Tinxy smart devices due to storage of credentials in plaintext within the device firmware. An attacker with physical access could exploit this by extracting the firmware and analyzing the binary data to obtain the plaintext credentials stored on the vulnerable device.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-2189

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • This vulnerability is reported by Shravan Singh from Mumbai, India.

Affected Vendor

Mogify Infotech

View all reports →

Affected Software

Tinxy Wi-Fi Lock Controller v1 RF, Tinxy Door Lock with Wi-Fi Controller, Tinxy 1 Node 10A and 16A Smart Wi-Fi Switches, Tinxy 2, 4 and 6 Node Smart Wi-Fi Switches, Tinxy Smart 15 Watts 3 in 1 Square Panel Ceiling Light, Tinxy Smart 8 Watts 3 in 1 Round Panel Ceiling Light
Vulnerable Versions:
all versions

Timeline

Official Publish: March 11th, 2025
Last Modified: March 11th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)