CVE-2023-27098
TP-Link Tapo APK up to v2.12.703 uses hardcoded credentials for access to the login panel.
CVSS
7.5
Alto
EPSS
0.4%
p32
KEV
—
Exploit Today
10
0-100
Publicado: 9 ene 2024 · Última mod.: 9 jul 2026 · CWE-312
0.4%EPSS · 30 días0.4%
2026-08-232026-09-20
TP-Link Tapo APK up to v2.12.703 uses hardcoded credentials for access to the login panel.
- github.comhttps://github.com/c0d3x27/CVEs/tree/main/CVE-2023-27098
- www.tp-link.comhttps://www.tp-link.com/support/contact-technical-support/#LiveChat-Support
- github.comhttps://github.com/c0d3x27/CVEs/tree/main/CVE-2023-27098
- www.tp-link.comhttps://www.tp-link.com/support/contact-technical-support/#LiveChat-Support
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-937646.5 MED0.9%
——0Mongoid may omit encryption rules for fields declared on embedded models when generating the client-side field-level encryption schema. Applications that enable this feature can therefore store values intended to be encrypted in readable form, with no error or warning. A party with routine read access to the database, a backup, or the underlying data files may then see data that was meant to remain unreadable outside the application.3dCVE-2026-937636.5 MED1.0%
——0A protection mechanism failure in the object-document mapper's encryption configuration generation can cause fields that an application declared for client-side field-level encryption to be written and kept in cleartext, without any error or warning. A party holding ordinary read access to the database can then read values that were intended to be protected from that party. This may result in unintended disclosure of sensitive information.3dCVE-2026-813219.8 CRÍ10.4%
——3CM2507 IP cameras store configured wireless network credentials in cleartext within the device filesystem. An attacker who obtains filesystem access through physical access, a debugging interface, or another vulnerability could recover the configured network identifier and pre-shared key.2dCVE-2026-634065.9 MED16.1%
——5AnyCable is a realtime server for reliable two-way communication that supports any backend. Prior to 1.6.15, the telemetry subsystem in telemetry/config.go enables tracking with a hardcoded public authToken, while clusterFingerprint in telemetry/telemetry.go reads the full configuration file and raw os.Args returned by anycableCLIArgs, including values supplied through --secret, --jwt_secret, and --http_rpc_secret. These inputs are passed to generateDigest, where sha256.New produces the hexadecimal fingerprint that is sent as telemetry. The available source therefore does not show raw credentials leaving the process or establish the advisory's claimed confidentiality loss, although the stable fingerprint is derived from secret-bearing configuration and the default telemetry client uses publicly known authentication material. This issue is fixed in version 1.6.15.3dCVE-2026-449405.7 MED3.3%
——1The rancher-extension-stackstate extension in SUSE Observability exposes service tokens in plain configuration or insecure locations rather than managing them securely. An attacker with minimal access could obtain the token to gain unauthorized access or escalate privileges within the observability environment.3dCVE-2026-86443—0.9%
——0Cleartext storage of sensitive information in the DuoxMe application for Android, in versions prior to 4.3.4, allows an attacker with local access to the device to retrieve the credentials stored by the application and impersonate the user account.3d