Tapplock develops smart lock hardware and associated firmware, with a vulnerability profile concentrated around authentication and information-disclosure weaknesses in its product line and device firmware. The durable signal centers on improper access control and exposure of sensitive information, reflecting the access-management demands inherent to connected physical security devices. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tapplock over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-20957HIGH The Bluetooth Low Energy (BLE) subsystem on Tapplock devices before 2018-06-12 allows replay attacks. | Aug 8, 2019 | 8.8 | 26 | NO | NO |
CVE-2018-20958MEDIUM The Bluetooth Low Energy (BLE) subsystem on Tapplock devices before 2018-06-12 relies on Key1 and SerialNo for unlock operations; however, these are derived from the MAC address, w | Aug 7, 2019 | 6.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tapplock.
Media articles that mention a CVE ID that affects a product developed by Tapplock — matched by CVE ID, not by vendor name.