CVE-2025-2189

Information Disclosure Vulnerability in Tinxy Smart Devices

Description

This vulnerability exists in the Tinxy smart devices due to storage of credentials in plaintext within the device firmware. An attacker with physical access could exploit this by extracting the firmware and analyzing the binary data to obtain the plaintext credentials stored on the vulnerable device.

Remediation

Solution:

  • Apply mitigations as per vendor instructions (whenever available) or discontinue the use of the product if mitigations are unavailable.

Workaround:

  • Perform risk assessment and implement physical security controls to prevent unauthorized access to the device.

Category

5.1
CVSS
Severity: Medium
CVSS 4.0 •
EPSS 0.01%
Third-Party Advisory org.in
Affected: Mogify Infotech Tinxy Wi-Fi Lock Controller v1 RF
Affected: Mogify Infotech Tinxy Door Lock with Wi-Fi Controller
Affected: Mogify Infotech Tinxy 1 Node 10A and 16A Smart Wi-Fi Switches
Affected: Mogify Infotech Tinxy 2, 4 and 6 Node Smart Wi-Fi Switches
Affected: Mogify Infotech Tinxy Smart 15 Watts 3 in 1 Square Panel Ceiling Light
Affected: Mogify Infotech Tinxy Smart 8 Watts 3 in 1 Round Panel Ceiling Light
Published at:
Updated at:

References

Frequently Asked Questions

What is the severity of CVE-2025-2189?
CVE-2025-2189 has been scored as a medium severity vulnerability.
How to fix CVE-2025-2189?
To fix CVE-2025-2189: Apply mitigations as per vendor instructions (whenever available) or discontinue the use of the product if mitigations are unavailable.
Is CVE-2025-2189 being actively exploited in the wild?
As for now, there are no information to confirm that CVE-2025-2189 is being actively exploited. According to its EPSS score, there is a ~0% probability that this vulnerability will be exploited by malicious actors in the next 30 days.
What software or system is affected by CVE-2025-2189?
CVE-2025-2189 affects Mogify Infotech Tinxy Wi-Fi Lock Controller v1 RF, Mogify Infotech Tinxy Door Lock with Wi-Fi Controller, Mogify Infotech Tinxy 1 Node 10A and 16A Smart Wi-Fi Switches, Mogify Infotech Tinxy 2, 4 and 6 Node Smart Wi-Fi Switches, Mogify Infotech Tinxy Smart 15 Watts 3 in 1 Square Panel Ceiling Light, Mogify Infotech Tinxy Smart 8 Watts 3 in 1 Round Panel Ceiling Light.
This platform uses data from the NIST NVD, MITRE CVE, MITRE CWE, First.org and CISA KEV but is not endorsed or certified by these entities. CVE is a registred trademark of the MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. CWE is a registred trademark of the MITRE Corporation and the authoritative source of CWE content is MITRE's CWE web site.
© 2025 Under My Watch. All Rights Reserved.