NA

CVE-2023-27126

Published: 06/06/2023 Updated: 12/06/2023
CVSS v3 Base Score: 4.6 | Impact Score: 3.6 | Exploitability Score: 0.9
VMScore: 0

Vulnerability Summary

The AES Key-IV pair used by the TP-Link TAPO C200 camera V3 (EU) on firmware version 1.1.22 Build 220725 is reused across all cameras. An attacker with physical access to a camera is able to extract and decrypt sensitive data containing the Wifi password and the TP-LINK account credential of the victim.

Vulnerable Product Search on Vulmon Subscribe to Product

tp-link tapo_c200_firmware 1.2.2