Hardcoded Credential Vulnerability in TP-Link Tapo APK
CVE-2023-27098

7.5HIGH

Key Information:

Vendor

TP-Link

Status
Vendor
CVE Published:
9 January 2024

What is CVE-2023-27098?

The TP-Link Tapo APK has a significant security flaw due to the use of hardcoded credentials that grant access to the login panel. This issue exposes users to potential unauthorized access, allowing malicious actors to exploit the app without proper authentication. It is advisable for users to upgrade to the latest version of the app as well as follow security best practices to safeguard their accounts and personal information.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.