The Bluetooth Low Energy (BLE) subsystem on Tapplock devices before 2018-06-12 relies on Key1 and SerialNo for unlock operations; however, these are derived from the MAC address, which is broadcasted by the device.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://www.pentestpartners.com/security-blog/totally-pwning-the-tapplock-smart-lock/ | third party advisory |
https://tapplock.com/notice/20180612/ | vendor advisory |