CyberRota Analysis
AI-GeneratedThe Tapo C120 v1 and C200 V5 cameras are vulnerable due to inadequate protection of login challenge data and insufficient input sanitization in the MacTool handler. An unauthenticated attacker on the same local network can exploit this vulnerability to replay login data, gain administrative access, enable a privileged service, and execute arbitrary commands, compromising the device's confidentiality, integrity, and availability. Organizations using these devices should prioritize remediation to prevent potential unauthorized access and control over their camera systems.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Tapo C120 v1 and C200 V5 do not adequately protect login challenge data or sanitize attacker-controlled input processed by the MacTool handler. An unauthenticated attacker on the same local network can replay login challenge data to obtain an administrative session, enable a privileged service that becomes accessible after a reboot, and submit crafted input to execute arbitrary commands within the device management process. Successful exploitation may allow arbitrary command execution on the camera and compromise the confidentiality, integrity, and availability of the affected device. Exploitation requires access from the same local network, replay of the login challenge data, activation of the privileged service, and a device reboot.