CVE-2025-1099
Information Disclosure Vulnerability in TP-Link Tapo C500 Wi-Fi Camera
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The TP-Link Tapo C500 V1 and V2 are a pan-and-tilt outdoor Wi-Fi security cameras designed for comprehensive surveillance. This vulnerability exists in Tapo C500 Wi-Fi camera due to hard-coded RSA private key embedded within the device firmware. An attacker with physical access could exploit this vulnerability to obtain cryptographic private keys which can then be used to perform impersonation, data decryption and man in the middle attacks on the targeted device.
This vulnerability exists in Tapo C500 Wi-Fi camera due to hard-coded RSA private key embedded within the device firmware. An attacker with physical access could exploit this vulnerability to obtain cryptographic private keys which can then be used to perform impersonation, data decryption and man in the middle attacks on the targeted device.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2025-02-07 CVE Reserved
- 2025-02-10 CVE Published
- 2025-02-11 EPSS Updated
- 2025-02-14 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-321: Use of Hard-coded Cryptographic Key
CAPEC
References (1)
URL | Tag | Source |
---|---|---|
https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2025-0017 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
TP-Link Search vendor "TP-Link" | Tapo C500 V1 Wi-Fi Camera Search vendor "TP-Link" for product "Tapo C500 V1 Wi-Fi Camera" | <= 1.1.4 Search vendor "TP-Link" for product "Tapo C500 V1 Wi-Fi Camera" and version " <= 1.1.4" | en |
Affected
| ||||||
TP-Link Search vendor "TP-Link" | Tapo C500 V2 Wi-Fi Camera Search vendor "TP-Link" for product "Tapo C500 V2 Wi-Fi Camera" | <= 1.0.2 Search vendor "TP-Link" for product "Tapo C500 V2 Wi-Fi Camera" and version " <= 1.0.2" | en |
Affected
|