CVE-2023-2759: Taphome Core Firmware
High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.
A hidden API exists in TapHome's core platform before version 2023.2 that allows an authenticated, low privileged user to change passwords of other users without any prior knowledge. The attacker may gain full access to the device by using this vulnerability.
Affected products
- Taphome Core Firmware: before 2023.2 (fixed in 2023.2)
Published 2023-07-17. Last modified 2026-06-17.