CVE-2023-38907

An issue in TPLink Smart Bulb Tapo series L530 before 1.2.4, L510E before 1.1.0, L630 before 1.0.4, P100 before 1.5.0, and Tapo Application 2.8.14 allows a remote attacker to replay old messages encrypted with a still valid session key.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:tp-link:tapo_l530e_firmware:1.0.0:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:tapo_l530e:-:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:a:tp-link:tapo:2.8.14:*:*:*:*:*:*:*

History

No history.

Information

Published : 2023-09-25 23:15

Updated : 2024-05-07 15:15


NVD link : CVE-2023-38907

Mitre link : CVE-2023-38907

CVE.ORG link : CVE-2023-38907


JSON object : View

Products Affected

tp-link

  • tapo_l530e
  • tapo
  • tapo_l530e_firmware