Researchers from the University of London along with Universita di Catania in Italy discovered four significant vulnerabilities in the popular TP-Link smart bulb and the Tapo app. This, according to researchers, underscores the broader security concerns around smart IoT devices.
The vulnerabilities identified with the TP-Link Tapo L530E smart bulb range from medium to high severity in their vulnerability score. The most dangerous allows attackers to impersonate the device during the session key exchange, giving the attacker a chance to steal user passwords and manipulate the devices.
Another potentially dangerous flaw comes from a hard-coded short checksum shared secret, meaning the “secret” used for authentication or encryption doesn’t change. Attackers can obtain it through brute forcing or by decompiling the app.
Among all possible attack scenarios, the most worrying is a combination use of the two. This allows the attacker to impersonate the bulb to retrieve the account details, then extract the user’s Wi-Fi SSID, and compromise all other devices connected to the network.
The vulnerabilities were first reported by Bleeping computer, who have since reached out to TP-Link. The company acknowledged all the findings and said they would implement fixes to the app and bulb’s firmware “in due course”.
During their assessment of the TP-Link bulb, the researchers found that “Exploiting the vulnerabilities was moderately challenging but devising appropriate fixes was harder.”
This study comes on the backdrop of IoT devices in the UK expected to grow to over 150 million next year, up from just 13 million in 2006 according to the UK Government. The same report also notes that the most growth will be in the automotive markets, and consumer electronics and utilities sectors.
Recommended
- The 12 Most Popular UK Smart Home Devices
- 7 Emerging IoT Tech Trends
- Businesses and Homes Can be Hacked Via Light Bulbs
Another report by Eco Experts also found that almost a quarter (23%) of 66.4 million Brits own at least one smart item, and over half (57%) of homes in the UK contain a smart device.
In relation, another report by Banklesstimes found that four in ten smart home devices may be vulnerable to cyber-attacks, and 68% of these are due to weak credentials, allowing the attackers to glean passwords like the researchers discovered in the TP-Link bulb.
In response to the discovery, the experts suggest isolating IoT devices from your network to limit potential exposure, update firmware and apps regularly, and use multi-factor authentication on accounts associated with the IoT devices for an extra layer of security.





