CVE-2023-38907: TP-Link Tapo
High severity, CVSS 7.5. EPSS: 1% chance of exploitation in the next 30 days.
An issue in TPLink Smart Bulb Tapo series L530 before 1.2.4, L510E before 1.1.0, L630 before 1.0.4, P100 before 1.5.0, and Tapo Application 2.8.14 allows a remote attacker to replay old messages encrypted with a still valid session key.
Affected products
Published 2023-09-25. Last modified 2026-06-17.