Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m3hf-h8r4-hrgj

Опубликовано: 11 мар. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 5.1

Описание

This vulnerability exists in the Tinxy smart devices due to storage of credentials in plaintext within the device firmware. An attacker with physical access could exploit this by extracting the firmware and analyzing the binary data to obtain the plaintext credentials stored on the vulnerable device.

This vulnerability exists in the Tinxy smart devices due to storage of credentials in plaintext within the device firmware. An attacker with physical access could exploit this by extracting the firmware and analyzing the binary data to obtain the plaintext credentials stored on the vulnerable device.

EPSS

Процентиль: 8%
0.0003
Низкий

5.1 Medium

CVSS4

Дефекты

CWE-312

Связанные уязвимости

nvd
11 месяцев назад

This vulnerability exists in the Tinxy smart devices due to storage of credentials in plaintext within the device firmware. An attacker with physical access could exploit this by extracting the firmware and analyzing the binary data to obtain the plaintext credentials stored on the vulnerable device.

EPSS

Процентиль: 8%
0.0003
Низкий

5.1 Medium

CVSS4

Дефекты

CWE-312