Ghostwire

CVE-2026-102368: Affected Tapo device firmware stores device-specific cryptographic material in plaintext within nonvolatile storage. An...

MEDIUM CVSS 0.0 EPSS 0.10%

Published: October 8, 2026 | Last Modified: October 8, 2026

Description

Affected Tapo device firmware stores device-specific cryptographic material in plaintext within nonvolatile storage. An attacker with physical access to an affected device can recover this sensitive material from the firmware. Successful exploitation of this vulnerability may result in the disclosure of device-specific cryptographic material and could, under certain conditions, increase the risk of unauthorized access to related protected information or communications.

Ghostwire Analysis — What This Means Practically

Exploitation Probability (EPSS): Low — 0.10% (1th percentile)

Low exploitation probability based on current threat landscape data. Standard patching timeline is appropriate.

This analysis is generated by Ghostwire from NVD, CISA KEV, EPSS, and open-source intelligence data. Verify findings through primary sources before acting.

Security Coverage (1 articles)

References