PT-2024-1169 · Tp Link · C200 Wifi Camera+1

Vineethkumarm

·

Published

2024-01-16

·

Updated

2024-07-03

·

CVE-2023-49515

CVSS v3.1

4.6

Medium

VectorAV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions TP Link TC70 and C200 WIFI Camera versions 1.3.4 through 1.3.10
Description The issue is related to insecure permissions in the firmware of TP Link TC70 and C200 WIFI Cameras, allowing a physically proximate attacker to obtain sensitive information via a connection to the UART pin components. This could potentially lead to unauthorized access to protected information.
Recommendations For TP Link TC70 and C200 WIFI Camera versions 1.3.4 through 1.3.10, update the firmware to version 1.3.11 to resolve the issue. As a temporary workaround, consider restricting physical access to the UART pin components to minimize the risk of exploitation.

Exploit

Fix

Information Disclosure

Insecure Storage of Sensitive Information

Weakness Enumeration

Related Identifiers

BDU:2024-00495
CVE-2023-49515

Affected Products

C200 Wifi Camera
Tp Link Tc70