<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 10 Oct 2026 15:08:32 +0000</lastBuildDate>
    <item>
      <title>CVE-2025-2189 — Information Disclosure Vulnerability in Tinxy Smart Devices</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2025-2189</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Mogify Infotech Tinxy Wi-Fi Lock Controller v1 RF, Mogify Infotech Tinxy Door Lock with Wi-Fi Controller, Mogify Infotech Tinxy 1 Node 10A and 16A Smart Wi-Fi Switches, Mogify Infotech Tinxy 2, 4 and 6 Node Smart Wi-Fi Switches, Mogify Infotech Tinxy Smart 15 Watts 3 in 1 Square Panel Ceiling Light, Mogify Infotech Tinxy Smart 8 Watts 3 in 1 Round Panel Ceiling Light&lt;/p&gt;
&lt;p&gt;This vulnerability exists in the Tinxy smart devices due to storage of credentials in plaintext within the device firmware. An attacker with physical access could exploit this by extracting the firmware and analyzing the binary data to obtain the plaintext credentials stored on the vulnerable device.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Mogify Infotech Tinxy Wi-Fi Lock Controller v1 RF, Mogify Infotech Tinxy Door Lock with Wi-Fi Controller, Mogify Infotech Tinxy 1 Node 10A and 16A Smart Wi-Fi Switches, Mogify Infotech Tinxy 2, 4 and 6 Node Smart Wi-Fi Switches, Mogify Infotech Tinxy Smart 15 Watts 3 in 1 Square Panel Ceiling Light, Mogify Infotech Tinxy Smart 8 Watts 3 in 1 Round Panel Ceiling Light&lt;/p&gt;
&lt;p&gt;This vulnerability exists in the Tinxy smart devices due to storage of credentials in plaintext within the device firmware. An attacker with physical access could exploit this by extracting the firmware and analyzing the binary data to obtain the plaintext credentials stored on the vulnerable device.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2025-2189</guid>
    </item>
  </channel>
</rss>
