CVE-2023-27098: High severity TP-Link Tapo Android vulnerability
Published Jan 9, 2024
·Updated
TP-Link Tapo APK up to v2.12.703 uses hardcoded credentials for access to the login panel.
Affected Software
2 affected components
All of the following
TP-Link Tapo Android<2.11.44
TP-Link Tapo C200
Event History
Jan 9, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·02:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-27098?
CVE-2023-27098 is classified as a critical vulnerability due to the use of hardcoded credentials.
2
How do I fix CVE-2023-27098?
To fix CVE-2023-27098, you should update the Tapo app to version 2.12.703 or later.
3
Which versions of the Tapo app are affected by CVE-2023-27098?
CVE-2023-27098 affects TP-Link Tapo APK versions up to 2.11.44.
4
What is the impact of CVE-2023-27098 on users?
The impact of CVE-2023-27098 on users is potential unauthorized access to the Tapo app due to hardcoded credentials.
5
What devices are safe from CVE-2023-27098?
Devices that use TP-Link Tapo APK version 2.12.703 or newer are not vulnerable to CVE-2023-27098.