PT-2024-1169 · Tp Link · C200 Wifi Camera+1
Vineethkumarm
·
Published
2024-01-16
·
Updated
2024-07-03
·
CVE-2023-49515
CVSS v3.1
4.6
Medium
| Vector | AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
TP Link TC70 and C200 WIFI Camera versions 1.3.4 through 1.3.10
Description
The issue is related to insecure permissions in the firmware of TP Link TC70 and C200 WIFI Cameras, allowing a physically proximate attacker to obtain sensitive information via a connection to the UART pin components. This could potentially lead to unauthorized access to protected information.
Recommendations
For TP Link TC70 and C200 WIFI Camera versions 1.3.4 through 1.3.10, update the firmware to version 1.3.11 to resolve the issue. As a temporary workaround, consider restricting physical access to the UART pin components to minimize the risk of exploitation.
Exploit
Fix
Information Disclosure
Insecure Storage of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
C200 Wifi Camera
Tp Link Tc70