Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-102368— Plaintext Storage of a Device-Specific Private Key in Tapo S505 Firmware

Quick assessment

Affected
TP-Link System Inc. Tapo S505 v1.6
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

受影响的 Tapo 设备固件将特定于设备的密码学材料以明文形式存储在非易失性存储中。具备设备物理访问权限的攻击者可以从固件中恢复这些敏感材料。 成功利用此漏洞可能导致特定于设备的密码学材料泄露,并在某些条件下,增加对受保护信息或通信进行未授权访问的风险。

CVSS 5.4 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-102368

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Plaintext Storage of a Device-Specific Private Key in Tapo S505 Firmware
Source: CVE Program / CVE List V5
Vulnerability Description
Affected Tapo device firmware stores device-specific cryptographic material in plaintext within nonvolatile storage. An attacker with physical access to an affected device can recover this sensitive material from the firmware.  Successful exploitation of this vulnerability may result in the disclosure of device-specific cryptographic material and could, under certain conditions, increase the risk of unauthorized access to related protected information or communications.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
敏感数据的明文存储
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
TP-Link System Inc. Tapo S505 v1.6 0 ~ 1.4.1 Build 260713 -

II. Public POCs for CVE-2026-102368

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-102368

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-102368 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-102368

No comments yet


Leave a comment