The IoT Breaches your Household Again
Davide Bonaventura, Sergio Esposito, Giampaolo Bella

TL;DR
This paper uncovers security vulnerabilities in Tp-Link Tapo smart devices, demonstrating how malicious actors can exploit these to access sensitive credentials and network information, thereby exposing users to significant risks.
Contribution
It introduces a novel attack scenario on Tapo devices and shows how these vulnerabilities can be exploited across multiple IoT devices within the same ecosystem.
Findings
Certain Tapo devices are fully exploitable with all attack scenarios.
Some devices are vulnerable to only specific attack scenarios.
The vulnerabilities can be replicated across similar IoT devices.
Abstract
Despite their apparent simplicity, devices like smart light bulbs and electrical plugs are often perceived as exempt from rigorous security measures. However, this paper challenges this misconception, uncovering how vulnerabilities in these seemingly innocuous devices can expose users to significant risks. This paper extends the findings outlined in previous work, introducing a novel attack scenario. This new attack allows malicious actors to obtain sensitive credentials, including the victim's Tapo account email and password, as well as the SSID and password of her local network. Furthermore, we demonstrate how these findings can be replicated, either partially or fully, across other smart devices within the same IoT ecosystem, specifically those manufactured by Tp-Link. Our investigation focused on the Tp-Link Tapo range, encompassing smart bulbs (Tapo L530E, Tapo L510E V2, and Tapo…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
