Description
Affected Tapo device firmware stores device-specific cryptographic material in plaintext within nonvolatile storage. An attacker with physical access to an affected device can recover this sensitive material from the firmware. Successful exploitation of this vulnerability may result in the disclosure of device-specific cryptographic material and could, under certain conditions, increase the risk of unauthorized access to related protected information or communications.
Related CPE's
Could not find any relations
References
Weaknesses
f23511db-6c3e-4e32-a477-6aa17d310630
CVSS impact metrics
CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
5.4 · Medium
Information
Source identifier
f23511db-6c3e-4e32-a477-6aa17d310630
Vulnerability status
Deferred
Published
2026-10-08T21:17:51.397Z
11 hours agoLast modified
2026-10-08T21:35:24.090Z
11 hours ago