{"id":"CVE-2026-102368","title":"Affected Tapo device firmware stores device-specific cryptographic material in plaintext within nonvolatile storage","summary":"Affected Tapo device firmware stores device-specific cryptographic material in plaintext within nonvolatile storage. An attacker with physical access to an affected device can recover this sensitive material from the firmware. \n\nSuccessf…","severity":"none","cwe":["CWE-312"],"published":"2026-10-08","updated":"2026-10-09","sourceUpdated":"2026-10-09T12:17:07.203","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-102368","references":[{"url":"https://www.tp-link.com/us/support/download/tapo-s505/#Firmware-Release-Notes","label":"f23511db-6c3e-4e32-a477-6aa17d310630"},{"url":"https://www.tp-link.com/us/support/faq/5332/","label":"f23511db-6c3e-4e32-a477-6aa17d310630"}],"tags":["nvd"],"ingestedAt":"2026-10-08T22:11:53.856Z","slug":"CVE-2026-102368","body":"## Overview\n\nAffected Tapo device firmware stores device-specific cryptographic material in plaintext within nonvolatile storage. An attacker with physical access to an affected device can recover this sensitive material from the firmware. \n\nSuccessful exploitation of this vulnerability may result in the disclosure of device-specific cryptographic material and could, under certain conditions, increase the risk of unauthorized access to related protected information or communications.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}