Vulnerability Description
An issue in TPLink Smart Bulb Tapo series L530 before 1.2.4, L510E before 1.1.0, L630 before 1.0.4, P100 before 1.5.0, and Tapo Application 2.8.14 allows a remote attacker to obtain sensitive information via the TSKEP authentication function.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Tp-Link | Tapo | 2.8.14 |
| Tp-Link | Tapo L530E Firmware | 1.0.0 |
| Tp-Link | Tapo L530E | - |
References
- https://arxiv.org/abs/2308.09019Third Party Advisory
- https://arxiv.org/pdf/2308.09019.pdfTechnical DescriptionThird Party Advisory
- https://www.dmi.unict.it/giamp/smartbulbscanbehackedtohackintoyourhousehold/
- https://www.scitepress.org/Papers/2023/120929/120929.pdf
- https://www.scitepress.org/PublicationsDetail.aspx?ID=X/auBv7JrSo=&t=1Third Party Advisory
- https://arxiv.org/abs/2308.09019Third Party Advisory
- https://arxiv.org/pdf/2308.09019.pdfTechnical DescriptionThird Party Advisory
- https://www.dmi.unict.it/giamp/smartbulbscanbehackedtohackintoyourhousehold/
- https://www.scitepress.org/Papers/2023/120929/120929.pdf
- https://www.scitepress.org/PublicationsDetail.aspx?ID=X/auBv7JrSo=&t=1Third Party Advisory
FAQ
What is CVE-2023-38908?
CVE-2023-38908 is a vulnerability with a CVSS score of 6.5 (MEDIUM). An issue in TPLink Smart Bulb Tapo series L530 before 1.2.4, L510E before 1.1.0, L630 before 1.0.4, P100 before 1.5.0, and Tapo Application 2.8.14 allows a remote attacker to obtain sensitive informat...
How severe is CVE-2023-38908?
CVE-2023-38908 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-38908?
Check the references section above for vendor advisories and patch information. Affected products include: Tp-Link Tapo, Tp-Link Tapo L530E Firmware, Tp-Link Tapo L530E.