8.8

CVE-2025-15557

Improper Certificate Validation in TP-Link Tapo H100 and P100 Allows Man-in-the-Middle Attack

An Improper Certificate Validation vulnerability in TP-Link Tapo H100 v1 and Tapo P100 v1 allows an on-path attacker on the same network segment to intercept and modify encrypted device-cloud communications.  This may compromise the confidentiality and integrity of device-to-cloud communication, enabling manipulation of device data or operations.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Tp-link ≫ Tapo H100 Firmware Version < 1.6.1
   Tp-link ≫ Tapo H100 Version 1.0
Tp-link ≫ Tapo P100 Firmware Version < 1.2.6
   Tp-link ≫ Tapo P100 Version 1.0
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.18% 0.079
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.8 2.8 5.9
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
f23511db-6c3e-4e32-a477-6aa17d310630 7.5 0 0
CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE-295 Improper Certificate Validation

The product does not validate, or incorrectly validates, a certificate.

https://www.tp-link.com/us/support/download/tapo-h100/
Product
https://www.tp-link.com/us/support/download/tapo-p100/
Product
https://www.tp-link.com/en/support/download/tapo-h100/
Product
https://www.tp-link.com/en/support/download/tapo-p100/
Product
https://www.tp-link.com/us/support/faq/4949/
Vendor Advisory