Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-10523


This vulnerability exists in TP-Link IoT Smart Hub due to storage of Wi-Fi credentials in plain text within the device firmware. An attacker with physical access could exploit this by extracting the firmware and analyzing the binary data to obtain the Wi-Fi credentials stored on the vulnerable device.


Published

2024-11-04T12:16:09.217

Last Modified

2024-11-08T15:14:30.070

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 4.6 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-312

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System tp-link tapo_h100_firmware < 1.5.22 Yes
Hardware tp-link tapo_h100 1.0 No

References