Information Disclosure in TPLink Smart Bulb Tapo Series by TPLink
CVE-2023-38908
6.5MEDIUM
Summary
A vulnerability in the TPLink Smart Bulb Tapo series permits remote attackers to access sensitive information due to flaws within the TSKEP authentication function. This affects specific models and app versions, leading to potential exploitation within users' home networks.
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved