CVE-2025-1099

This vulnerability exists in Tapo C500 Wi-Fi camera due to hard-coded RSA private key embedded within the device firmware. An attacker with physical access could exploit this vulnerability to obtain cryptographic private keys which can then be used to perform impersonation, data decryption and man in the middle attacks on the targeted device.
CVSS

No CVSS.

Configurations

No configuration.

History

14 Feb 2025, 12:15

Type Values Removed Values Added
Summary
  • (es) Las cámaras de seguridad Wi-Fi para exteriores TP-Link Tapo C500 V1 y V2 son cámaras de seguridad Wi-Fi con movimiento horizontal y vertical diseñadas para una vigilancia integral. Esta vulnerabilidad existe en la cámara Wi-Fi Tapo C500 debido a una clave privada RSA codificada de forma rígida integrada en el firmware del dispositivo. Un atacante con acceso físico podría aprovechar esta vulnerabilidad para obtener claves privadas criptográficas que luego se pueden utilizar para realizar suplantaciones de identidad, descifrado de datos y ataques de intermediario en el dispositivo objetivo.
Summary (en) The TP-Link Tapo C500 V1 and V2 are a pan-and-tilt outdoor Wi-Fi security cameras designed for comprehensive surveillance. This vulnerability exists in Tapo C500 Wi-Fi camera due to hard-coded RSA private key embedded within the device firmware. An attacker with physical access could exploit this vulnerability to obtain cryptographic private keys which can then be used to perform impersonation, data decryption and man in the middle attacks on the targeted device. (en) This vulnerability exists in Tapo C500 Wi-Fi camera due to hard-coded RSA private key embedded within the device firmware. An attacker with physical access could exploit this vulnerability to obtain cryptographic private keys which can then be used to perform impersonation, data decryption and man in the middle attacks on the targeted device.

10 Feb 2025, 11:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-10 11:15

Updated : 2025-02-14 12:15


NVD link : CVE-2025-1099

Mitre link : CVE-2025-1099

CVE.ORG link : CVE-2025-1099


JSON object : View

Products Affected

No product.

CWE
CWE-321

Use of Hard-coded Cryptographic Key