CVE-2024-10523

Severity CVSS v4.0:
MEDIUM
Type:
CWE-312 Cleartext Storage of Sensitive Information
Publication date:
04/11/2024
Last modified:
08/11/2024

Description

This vulnerability exists in TP-Link IoT Smart Hub due to storage of Wi-Fi credentials in plain text within the device firmware. An attacker with physical access could exploit this by extracting the firmware and analyzing the binary data to obtain the Wi-Fi credentials stored on the vulnerable device.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:tp-link:tapo_h100_firmware:*:*:*:*:*:*:*:* 1.5.22 (excluding)
cpe:2.3:h:tp-link:tapo_h100:1.0:*:*:*:*:*:*:*