Taphome's vulnerability footprint centers on its core product and associated firmware, where the observed weakness classes reflect input-handling and access-control issues in application logic, specifically SQL injection and authorization flaws. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Taphome over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-2759HIGH A hidden API exists in TapHome's core platform before version 2023.2 that allows an authenticated, low privileged user to change passwords of other users without any prior knowledg | Jul 17, 2023 | 8.8 | 24 | NO | NO |
CVE-2023-2760HIGH An SQL injection vulnerability exists in TapHome core HandleMessageUpdateDevicePropertiesRequest function before version 2023.2, allowing low privileged users to inject arbitrary S | Jul 17, 2023 | 7.6 | 22 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Taphome.
Media articles that mention a CVE ID that affects a product developed by Taphome — matched by CVE ID, not by vendor name.