CERT-In Vulnerability Note
CIVN-2024-0331
Information Disclosure Vulnerability in TP-Link IoT Smart Hub
Original Issue Date:November 04, 2024
Severity Rating: MEDIUM
Systems Affected
- TP-Link Tapo H100 IoT Smart Hub with Chime - hardware version V1 and firmware versions prior to 1.5.22
Overview
A vulnerability has been reported in TP-Link IoT Smart Hub, which could allow an attacker to obtain sensitive information from the targeted devices.
Target Audience
End-users using TP-Link IoT Smart Hub.
Risk Assessment
Medium risk of Wi-Fi credential exposure.
Impact Assessment
Potential exposure of Wi-Fi credentials from TP-Link IoT Smart Hub.
Description
The TP-Link IoT Smart Hub is a device designed to manage and connect multiple smart home devices like lights, sensors and appliances within a single network.
This vulnerability exists in TP-Link IoT Smart Hub due to storage of Wi-Fi credentials in plain text within the device firmware. An attacker with physical access could exploit this by extracting the firmware and analyzing the binary data to obtain the Wi-Fi credentials stored on the vulnerable device.
Credit
This vulnerability is reported by Shravan Singh from Mumbai, India
Solution
- Upgrade TP-Link Tapo H100 IoT Smart Hub to firmware version 1.5.22
Vendor Information
TP-Link
https://www.tp-link.com/in/home-networking/smart-hub/tapo-h100/
References
TP-Link
https://www.tp-link.com/in/home-networking/smart-hub/tapo-h100/
CVE Name
CVE-2024-10523
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-22902657
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|