This vulnerability exists in Tapo C500 Wi-Fi camera due to hard-coded RSA private key embedded within the device firmware. An attacker with physical access could exploit this vulnerability to obtain cryptographic private keys which can then be used to perform impersonation, data decryption and man in the middle attacks on the targeted device.
CVSS
No CVSS.
References
Configurations
No configuration.
History
14 Feb 2025, 12:15
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
|
Summary | (en) This vulnerability exists in Tapo C500 Wi-Fi camera due to hard-coded RSA private key embedded within the device firmware. An attacker with physical access could exploit this vulnerability to obtain cryptographic private keys which can then be used to perform impersonation, data decryption and man in the middle attacks on the targeted device. |
10 Feb 2025, 11:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-02-10 11:15
Updated : 2025-02-14 12:15
NVD link : CVE-2025-1099
Mitre link : CVE-2025-1099
CVE.ORG link : CVE-2025-1099
JSON object : View
Products Affected
No product.
CWE
CWE-321
Use of Hard-coded Cryptographic Key