ID

VAR-202306-0535


CVE

CVE-2023-27126


TITLE

TP-LINK Tapo C200 Security hole

Trust: 0.6

sources: CNNVD: CNNVD-202306-404

DESCRIPTION

The AES Key-IV pair used by the TP-Link TAPO C200 camera V3 (EU) on firmware version 1.1.22 Build 220725 is reused across all cameras. An attacker with physical access to a camera is able to extract and decrypt sensitive data containing the Wifi password and the TP-LINK account credential of the victim

Trust: 0.99

sources: NVD: CVE-2023-27126 // VULMON: CVE-2023-27126

AFFECTED PRODUCTS

vendor:tp linkmodel:tapo c200scope:eqversion:1.2.2

Trust: 1.0

sources: NVD: CVE-2023-27126

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2023-27126
value: MEDIUM

Trust: 1.0

134c704f-9b21-4f2e-91b3-4a467353bcc0: CVE-2023-27126
value: MEDIUM

Trust: 1.0

CNNVD: CNNVD-202306-404
value: MEDIUM

Trust: 0.6

nvd@nist.gov: CVE-2023-27126
baseSeverity: MEDIUM
baseScore: 4.6
vectorString: CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
attackVector: PHYSICAL
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 0.9
impactScore: 3.6
version: 3.1

Trust: 2.0

sources: CNNVD: CNNVD-202306-404 // NVD: CVE-2023-27126 // NVD: CVE-2023-27126

PROBLEMTYPE DATA

problemtype:CWE-522

Trust: 1.0

sources: NVD: CVE-2023-27126

TYPE

other

Trust: 0.6

sources: CNNVD: CNNVD-202306-404

EXTERNAL IDS

db:NVDid:CVE-2023-27126

Trust: 1.7

db:CNNVDid:CNNVD-202306-404

Trust: 0.6

db:VULMONid:CVE-2023-27126

Trust: 0.1

sources: VULMON: CVE-2023-27126 // CNNVD: CNNVD-202306-404 // NVD: CVE-2023-27126

REFERENCES

url:http://tp-link.com

Trust: 1.7

url:https://www.claranet.fr/blog/dans-les-entrailles-dune-camera-connectee-tp-link-14

Trust: 1.7

url:http://tapo.com

Trust: 1.7

url:https://cxsecurity.com/cveshow/cve-2023-27126/

Trust: 0.6

url:https://nvd.nist.gov

Trust: 0.1

sources: VULMON: CVE-2023-27126 // CNNVD: CNNVD-202306-404 // NVD: CVE-2023-27126

SOURCES

db:VULMONid:CVE-2023-27126
db:CNNVDid:CNNVD-202306-404
db:NVDid:CVE-2023-27126

LAST UPDATE DATE

2025-01-08T23:07:34.414000+00:00


SOURCES UPDATE DATE

db:VULMONid:CVE-2023-27126date:2023-06-06T00:00:00
db:CNNVDid:CNNVD-202306-404date:2023-06-13T00:00:00
db:NVDid:CVE-2023-27126date:2025-01-08T16:15:27.993

SOURCES RELEASE DATE

db:VULMONid:CVE-2023-27126date:2023-06-06T00:00:00
db:CNNVDid:CNNVD-202306-404date:2023-06-06T00:00:00
db:NVDid:CVE-2023-27126date:2023-06-06T18:15:10.343