CVE detail
CVE-2023-2760 — CVE-2023-2760
Published 2023-07-17 · Modified 2026-06-17 · Vendor taphome · Product core_firmware · Source nvd
HIGH
severity
CVSS-derived band
0.0043
EPSS probability
exploitation probability, 30d
36.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
An SQL injection vulnerability exists in TapHome core HandleMessageUpdateDevicePropertiesRequest function before version 2023.2, allowing low privileged users to inject arbitrary SQL directives into an SQL query and execute arbitrary SQL commands and get full reading access. This may also lead to limited write access and temporary Denial-of-Service.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References