CVE-2025-4975
- EPSS 0.03%
- Published 22.05.2025 21:17:52
- Last modified 23.05.2025 15:54:42
When a notification relating to low battery appears for a user with whom the device has been shared, tapping the notification grants full access to the power settings of that device.
CVE-2024-31340
- EPSS 0.28%
- Published 22.05.2024 06:15:12
- Last modified 28.03.2025 20:15:23
TP-Link Tether versions prior to 4.5.13 and TP-Link Tapo versions prior to 3.3.6 do not properly validate certificates, which may allow a remote unauthenticated attacker to eavesdrop on an encrypted communication via a man-in-the-middle attack.
CVE-2023-27098
- EPSS 0.05%
- Published 09.01.2024 02:15:44
- Last modified 18.06.2025 17:15:26
TP-Link Tapo APK up to v2.12.703 uses hardcoded credentials for access to the login panel.
CVE-2023-34829
- EPSS 0.03%
- Published 28.12.2023 03:15:07
- Last modified 17.04.2025 21:15:46
Incorrect access control in TP-Link Tapo before v3.1.315 allows attackers to access user credentials in plaintext.
CVE-2023-38907
- EPSS 0.25%
- Published 25.09.2023 23:15:09
- Last modified 21.11.2024 08:14:25
An issue in TPLink Smart Bulb Tapo series L530 before 1.2.4, L510E before 1.1.0, L630 before 1.0.4, P100 before 1.5.0, and Tapo Application 2.8.14 allows a remote attacker to replay old messages encrypted with a still valid session key.
CVE-2023-38908
- EPSS 0.06%
- Published 22.08.2023 01:15:08
- Last modified 21.11.2024 08:14:25
An issue in TPLink Smart Bulb Tapo series L530 before 1.2.4, L510E before 1.1.0, L630 before 1.0.4, P100 before 1.5.0, and Tapo Application 2.8.14 allows a remote attacker to obtain sensitive information via the TSKEP authentication function.
CVE-2023-38909
- EPSS 0.05%
- Published 22.08.2023 01:15:08
- Last modified 21.11.2024 08:14:25
An issue in TPLink Smart Bulb Tapo series L530 before 1.2.4, L510E before 1.1.0, L630 before 1.0.4, P100 before 1.5.0, and Tapo Application 2.8.14 allows a remote attacker to obtain sensitive information via the IV component in the AES128-CBC functio...
CVE-2023-38906
- EPSS 0.05%
- Published 22.08.2023 00:15:07
- Last modified 21.11.2024 08:14:25
An issue in TPLink Smart Bulb Tapo series L530 1.1.9, L510E 1.0.8, L630 1.0.3, P100 1.4.9, Smart Camera Tapo series C200 1.1.18, and Tapo Application 2.8.14 allows a remote attacker to obtain sensitive information via the authentication code for the ...