First published: Wed Jan 17 2024(Updated: )
Insecure Permissiosn vulnerability in TP Link TC70 and C200 WIFI Camera v.3 firmware v.1.3.4 and fixed in v.1.3.11 allows a physically proximate attacker to obtain sensitive information via a connection to the UART pin components.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Any of | ||
TP-Link Tapo C200 | =1.1.22 | |
TP-Link Tapo C200 | =1.3.4 | |
TP-Link Tapo C200 | =1.3.9 | |
TP-Link Tapo C200 Firmware | =3 | |
All of | ||
Any of | ||
TP-Link Tapo TC70 | =1.1.22 | |
TP-Link Tapo TC70 | =1.3.4 | |
TP-Link Tapo TC70 | =1.3.9 | |
Tp-link Tapo Tc70 Firmware | =3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-49515 is classified as a high severity vulnerability due to the potential for unauthorized access to sensitive information.
To fix CVE-2023-49515, users should upgrade to the firmware version 1.3.11 or later for the affected TP-Link Tapo C200 and TC70 camera models.
CVE-2023-49515 affects users of TP-Link Tapo C200 and TC70 cameras running firmware versions 1.3.4, 1.3.9, or 1.1.22.
CVE-2023-49515 allows physically proximate attackers to obtain sensitive information through access to the UART pin components.
While the best course of action is to upgrade, temporarily limiting physical access to the affected devices can help mitigate the risk of CVE-2023-49515.