CVE-2026-102368

Betroffene Tapo-Geräte-Firmware speichert gerätespezifisches kryptografisches Material im Klartext in nichtflüchtigem Speicher.

mediumEPSS 0.1%

Description

Affected Tapo device firmware stores device-specific cryptographic material in plaintext within nonvolatile storage. An attacker with physical access to an affected device can recover this sensitive material from the firmware.  Successful exploitation of this vulnerability may result in the disclosure of device-specific cryptographic material and could, under certain conditions, increase the risk of unauthorized access to related protected information or communications.

Metrics

5.4
Source: cna-v4
0.9 %
Low — this CVE sits in the lower 10% of all CVEs scored today.
Show all metrics
Severity
medium
no public PoC known
0.1 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-10-08 20:54 UTC
CWE-312

Weakness classes (CWE)

  • CWE-312Base

    Cleartext Storage of Sensitive Information

    The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

    cwe.mitre.org →

References & sources

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. CVE Modified2026-10-09 12:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • SSVC: {"id":"CVE-2026-102368","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technical…
  2. New CVE Received2026-10-08 21:17 UTC· f23511db-6c3e-4e32-a477-6aa17d310630
    • Description: Affected Tapo device firmware stores device-specific cryptographic material in plaintext within nonvolatile storage. An attacker with physical access to an affected device can recover this sensitive material from the firmware.  Successful exploitation of this vulnerability may result in the disclosure of device-specific cryptographic material and could, under certain conditions, increase the risk of unauthorized access to related protected information or communications.
    • CVSS V4.0: AV:P/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
    • CWE: CWE-312
    • Affected: New affected value received. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/102xxx/CVE-2026-102368.json">CVE-2026-102368</a>