CVE-2023-38906: TP-Link Tapo

Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.

An issue in TPLink Smart Bulb Tapo series L530 1.1.9, L510E 1.0.8, L630 1.0.3, P100 1.4.9, Smart Camera Tapo series C200 1.1.18, and Tapo Application 2.8.14 allows a remote attacker to obtain sensitive information via the authentication code for the UDP message.

Affected products

  • TP-Link Tapo: version 2.8.14 only
  • TP-Link Tapo l530e Firmware: version 1.0.0 only

Published 2023-08-22. Last modified 2026-06-17.