HomeSecurityTP-Link smart light bulbs allow your Wi-Fi password to be stolen

TP-Link smart bulbs allow your Wi-Fi password to be stolen

Researchers from Italy and the United Kingdom have discovered four vulnerabilities in the TP-Link Tapo L530E smart light bulb and TP-Link's Tapo app, which could allow hackers to steal their target's Wi-Fi password.

The TP-Link Tapo L530E is a best-selling smart bulb on many marketplaces, including Amazon. TP-link Tapo is a smart device management app with 10 million installs on Google Play.

Researchers from the University of Catania and the University of London analyzed this product due to its popularity. However, the aim of their study is to highlight the security risks in the billions of smart IoT used by consumers, many of which follow insecure data transmission and weak authentication mechanisms.

See also: BlackCat ransomware gang hacked Seiko

TP-Link
TP-Link smart light bulbs let hackers steal your Wi-Fi password

Weaknesses of smart bulbs

The first vulnerability concerns improper authentication in the Tapo L503E, allowing attackers to impersonate the device during the session key exchange step.

This severe vulnerability (CVSS v3.1 score: 8.8) allows an adjacent hacker to recover Tapo users' passwords and compromise Tapo devices.

The second vulnerability is also a high severity issue (CVSS v3.1 score: 7.6) resulting from a hard-coded short shared secret checksum, which attackers can obtain through brute-forcing or by decompiling the Tapo application.

The third problem concerns a low-severity weakness that concerns the lack of randomness during symmetric encryption, making the cryptographic scheme predictable.

Finally, a fourth issue stems from the lack of checks for the freshness of received messages, keeping session keys valid for 24 hours, and allowing attackers to replay messages during this period.

See also: Google search results: Amazon ad leads to fraud

Attack scenarios

The most worrying attack scenario is the impersonation of the lamp and obtaining the Tapo user account details by exploiting vulnerabilities 1 and 2.

Then, through the Tapo app, the attacker can extract the SSID and password of the victim's wireless network and gain access to all other devices connected to that network.

The device must be in installation mode for the attack to succeed. However, the attacker can unplug the bulb, forcing the user to reinstall it to restore its functionality.

TP-Link

The other type of attack that the researchers are exploring is a MITM (Man-In-The-Middle) attack with a specific Tapo L530E device, exploiting vulnerability 1 to intercept and spoof the communication between the application and the light bulb, capturing the RSA encryption keys used for the subsequent data exchange.

MITM attacks are also possible with unconfigured Tapo devices, exploiting the same vulnerability by connecting them to WiFi during setup, bridging two networks and routing discovery messages, ultimately retrieving passwords , SSIDs and WiFi passwords in a base64-encrypted format that is easily decryptable.

Finally, vulnerability 4 allows attackers to perform replay attacks, replaying previously recorded messages in order to achieve functional changes to the device.

See also: Ivanti warns of a new MobileIron zero-day bug

TP-Link smart bulbs allow your Wi-Fi password to be stolen
TP-Link smart light bulbs let hackers steal your Wi-Fi password

Disclosure and repair

The university researchers responsibly reported their findings to TP-Link, and the supplier acknowledged all of them and informed them that it would implement fixes to both the app and the bulb firmware soon

However, the article does not clarify whether these fixes have already been made available and which versions remain vulnerable to attacks.

As a general tip for Internet of Things (IoT) security, it is recommended to keep such devices isolated from critical networks, use the latest available firmware updates and corresponding app versions, and protect accounts with multi-factor authentication (MFA) and strong passwords.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS