CVE-2025-1099 - CVE House
Back to Database
Status published High CVE-2025-1099

Information Disclosure Vulnerability in TP-Link Tapo C500 Wi-Fi Camera

Vulnerability Description

This vulnerability exists in Tapo C500 Wi-Fi camera due to hard-coded RSA private key embedded within the device firmware. An attacker with physical access could exploit this vulnerability to obtain cryptographic private keys which can then be used to perform impersonation, data decryption and man in the middle attacks on the targeted device.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-1099

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • This vulnerability is reported by Shravan Singh from Mumbai, India

Affected Vendor

Affected Software

Tapo C500 V1 Wi-Fi Camera, Tapo C500 V2 Wi-Fi Camera
Vulnerable Versions:
<=1.1.4, <=1.0.2

Timeline

Official Publish: February 10th, 2025
Last Modified: February 14th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)