TP-Link Tapo APK up to v2.12.703 uses hardcoded credentials for access to the login panel.
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.
Link | Tags |
---|---|
http://tp-link.com | product |
http://tp-lin.com | broken link |
https://www.tp-link.com/support/contact-technical-support/#LiveChat-Support | product |
https://github.com/c0d3x27/CVEs/tree/main/CVE-2023-27098 | exploit third party advisory |