CVE-2023-35717 HIGH

CVE-2023-35717: TP-Link Tapo C210 Password Recovery Authentication Bypass Vulnerability

Vendor Tp-Link
Product Tapo C210
Weakness CWE-640 · Weak password recovery
Published May 3, 2024
Last update September 18, 2024

CVSS base score

8.8/10
Attack vector Adjacent
Attack complexity Low
Privileges required None
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

TP-Link Tapo C210 Password Recovery Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of TP-Link Tapo C210 IP cameras. Authentication is not required to exploit this vulnerability. The specific flaw exists within the password recovery mechanism. The issue results from reliance upon the secrecy of the password derivation algorithm when generating a recovery password. An attacker can leverage this vulnerability to bypass authentication on the system. . Was ZDI-CAN-20484.

Key dates

02Disclosure timeline

May 3, 2024 CVE published
September 18, 2024 Record updated