Researchers from Italy and the United Kingdom have discovered four vulnerabilities in the TP-Link Tapo L530E smart light bulb and TP-Link's Tapo app, which could allow hackers to steal their target's Wi-Fi password.
The TP-Link Tapo L530E is a best-selling smart bulb on many marketplaces, including Amazon. TP-link Tapo is a smart device management app with 10 million installs on Google Play.
Researchers from the University of Catania and the University of London analyzed this product due to its popularity. However, the aim of their study is to highlight the security risks in the billions of smart IoT used by consumers, many of which follow insecure data transmission and weak authentication mechanisms.
See also: BlackCat ransomware gang hacked Seiko

Weaknesses of smart bulbs
The first vulnerability concerns improper authentication in the Tapo L503E, allowing attackers to impersonate the device during the session key exchange step.
This severe vulnerability (CVSS v3.1 score: 8.8) allows an adjacent hacker to recover Tapo users' passwords and compromise Tapo devices.
The second vulnerability is also a high severity issue (CVSS v3.1 score: 7.6) resulting from a hard-coded short shared secret checksum, which attackers can obtain through brute-forcing or by decompiling the Tapo application.
The third problem concerns a low-severity weakness that concerns the lack of randomness during symmetric encryption, making the cryptographic scheme predictable.
Finally, a fourth issue stems from the lack of checks for the freshness of received messages, keeping session keys valid for 24 hours, and allowing attackers to replay messages during this period.
See also: Google search results: Amazon ad leads to fraud
Attack scenarios
The most worrying attack scenario is the impersonation of the lamp and obtaining the Tapo user account details by exploiting vulnerabilities 1 and 2.
Then, through the Tapo app, the attacker can extract the SSID and password of the victim's wireless network and gain access to all other devices connected to that network.
The device must be in installation mode for the attack to succeed. However, the attacker can unplug the bulb, forcing the user to reinstall it to restore its functionality.

The other type of attack that the researchers are exploring is a MITM (Man-In-The-Middle) attack with a specific Tapo L530E device, exploiting vulnerability 1 to intercept and spoof the communication between the application and the light bulb, capturing the RSA encryption keys used for the subsequent data exchange.
MITM attacks are also possible with unconfigured Tapo devices, exploiting the same vulnerability by connecting them to WiFi during setup, bridging two networks and routing discovery messages, ultimately retrieving passwords , SSIDs and WiFi passwords in a base64-encrypted format that is easily decryptable.
Finally, vulnerability 4 allows attackers to perform replay attacks, replaying previously recorded messages in order to achieve functional changes to the device.
See also: Ivanti warns of a new MobileIron zero-day bug

Disclosure and repair
The university researchers responsibly reported their findings to TP-Link, and the supplier acknowledged all of them and informed them that it would implement fixes to both the app and the bulb firmware soon
However, the article does not clarify whether these fixes have already been made available and which versions remain vulnerable to attacks.
As a general tip for Internet of Things (IoT) security, it is recommended to keep such devices isolated from critical networks, use the latest available firmware updates and corresponding app versions, and protect accounts with multi-factor authentication (MFA) and strong passwords.
Information source: bleepingcomputer.com
