PT-2021-22198 · Tp Link · Tp-Link Ue330

Ben Nassi

+4

·

Published

2021-08-11

·

Updated

2021-08-23

·

CVE-2021-38543

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions TP-Link UE330 USB splitter devices through 2021-08-09
Description The issue allows remote attackers to recover speech signals from an LED on the device, via a telescope and an electro-optical sensor, also known as a "Glowworm" attack. This occurs when the device supplies power to audio-output equipment, such as speakers. The power indicator LED of the USB splitter is connected directly to the power line, and its intensity is correlative to the device's power consumption. The sound played by the connected speakers affects the USB splitter's power consumption, which in turn affects the light intensity of the LED. By analyzing measurements from an electro-optical sensor directed at the power indicator LED, it is possible to recover the sound played by the connected speakers.
Recommendations For TP-Link UE330 USB splitter devices through 2021-08-09, consider disabling the power indicator LED or restricting access to the device to minimize the risk of exploitation, until a fix is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2021-38543

Affected Products

Tp-Link Ue330