Vulnerability Description
Tinxy Door Lock with firmware before 3.2 allow attackers to unlock a door by replaying an Unlock request that occurred when the attacker was previously authorized. In other words, door-access revocation is mishandled.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Tinxy | Smart Wifi Door Lock Firmware | < 3.2 |
| Tinxy | Smart Wifi Door Lock | - |
Related Weaknesses (CWE)
References
- https://medium.com/%40avishek_75733/smart-products-are-always-not-that-smart-tin
- https://medium.com/%40avishek_75733/smart-products-are-always-not-that-smart-tin
FAQ
What is CVE-2020-9438?
CVE-2020-9438 is a vulnerability with a CVSS score of 5.9 (MEDIUM). Tinxy Door Lock with firmware before 3.2 allow attackers to unlock a door by replaying an Unlock request that occurred when the attacker was previously authorized. In other words, door-access revocati...
How severe is CVE-2020-9438?
CVE-2020-9438 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-9438?
Check the references section above for vendor advisories and patch information. Affected products include: Tinxy Smart Wifi Door Lock Firmware, Tinxy Smart Wifi Door Lock.