CVE-2026-102368
MEDIUM
5,4
Source: f23511db-6c3e-4e32-a477-6aa17d310630
Attack Vector: physical
Attack Complexity: low
Privileges Required: none
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A
Description
AI Translation Available
Affected Tapo device firmware stores device-specific cryptographic material in plaintext within nonvolatile storage. An attacker with physical access to an affected device can recover this sensitive material from the firmware.
Successful exploitation of this vulnerability may result in the disclosure of device-specific cryptographic material and could, under certain conditions, increase the risk of unauthorized access to related protected information or communications.
EPSS (Exploit Prediction Scoring System)
Trend Analysis
EPSS (Exploit Prediction Scoring System)
Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.
EPSS Score
0,0010
Percentile
0,0th
Updated
EPSS Score Trend (Last 3 Days)
312
Cleartext Storage of Sensitive Information
DraftCommon Consequences
Security Scopes Affected:
Confidentiality
Potential Impacts:
Read Application Data
Applicable Platforms
Technologies:
Cloud Computing, ICS/OT, Mobile
https://www.tp-link.com/us/support/download/tapo-s505/#Firmware-Release-Notes
https://www.tp-link.com/us/support/faq/5332/