Vulnerability Description
Insecure Permissiosn vulnerability in TP Link TC70 and C200 WIFI Camera v.3 firmware v.1.3.4 and fixed in v.1.3.11 allows a physically proximate attacker to obtain sensitive information via a connection to the UART pin components.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Tp-Link | Tapo C200 Firmware | 1.1.22 |
| Tp-Link | Tapo C200 | 3 |
| Tp-Link | Tapo Tc70 Firmware | 1.1.22 |
| Tp-Link | Tapo Tc70 | 3.0 |
Related Weaknesses (CWE)
References
- https://github.com/VineethKumarM/TAPO-TC70-Unauthorized-root-access-using-UARTExploitThird Party Advisory
- https://github.com/VineethKumarM/TAPO-TC70-Unauthorized-root-access-using-UART/tExploitThird Party Advisory
- https://github.com/VineethKumarM/TAPO-TC70-Unauthorized-root-access-using-UARTExploitThird Party Advisory
- https://github.com/VineethKumarM/TAPO-TC70-Unauthorized-root-access-using-UART/tExploitThird Party Advisory
FAQ
What is CVE-2023-49515?
CVE-2023-49515 is a vulnerability with a CVSS score of 4.6 (MEDIUM). Insecure Permissiosn vulnerability in TP Link TC70 and C200 WIFI Camera v.3 firmware v.1.3.4 and fixed in v.1.3.11 allows a physically proximate attacker to obtain sensitive information via a connecti...
How severe is CVE-2023-49515?
CVE-2023-49515 has been rated MEDIUM with a CVSS base score of 4.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-49515?
Check the references section above for vendor advisories and patch information. Affected products include: Tp-Link Tapo C200 Firmware, Tp-Link Tapo C200, Tp-Link Tapo Tc70 Firmware, Tp-Link Tapo Tc70.