---
id: CVE-2026-102368
title: >-
  Affected Tapo device firmware stores device-specific cryptographic material in
  plaintext within nonvolatile storage
summary: "Affected Tapo device firmware stores device-specific cryptographic material in plaintext within nonvolatile storage. An attacker with physical access to an affected device can recover this sensitive material from the firmware.\_\n\nSuccessf…"
severity: none
cwe:
  - CWE-312
published: '2026-10-08'
updated: '2026-10-09'
sourceUpdated: '2026-10-09T12:17:07.203'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-102368'
references:
  - url: >-
      https://www.tp-link.com/us/support/download/tapo-s505/#Firmware-Release-Notes
    label: f23511db-6c3e-4e32-a477-6aa17d310630
  - url: 'https://www.tp-link.com/us/support/faq/5332/'
    label: f23511db-6c3e-4e32-a477-6aa17d310630
tags:
  - nvd
ingestedAt: '2026-10-08T22:11:53.856Z'
---

## Overview

Affected Tapo device firmware stores device-specific cryptographic material in plaintext within nonvolatile storage. An attacker with physical access to an affected device can recover this sensitive material from the firmware. 

Successful exploitation of this vulnerability may result in the disclosure of device-specific cryptographic material and could, under certain conditions, increase the risk of unauthorized access to related protected information or communications.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
