Vulnerabilities
Vulnerable Software
Tp-Link:  >> Tapo  Security Vulnerabilities
A vulnerability in the certificate validation logic may allow applications to accept untrusted or improperly validated server identities during TLS communication. An attacker in a privileged network position may be able to intercept or modify traffic if they can position themselves within the communication channel. Successful exploitation may compromise confidentiality, integrity, and availability of application data.
CVSS Score
8.1
EPSS Score
0.0
Published
2026-02-13
A permissive web security configuration may allow cross-origin restrictions enforced by modern browsers to be bypassed under specific circumstances. Exploitation requires the presence of an existing client-side injection vulnerability and user access to the affected web interface. Successful exploitation could allow unauthorized disclosure of sensitive information. Fixed in updated Omada Cloud Controller service versions deployed automatically by TP‑Link. No user action is required.
CVSS Score
7.5
EPSS Score
0.0
Published
2026-02-13
TP-Link Tapo APK up to v2.12.703 uses hardcoded credentials for access to the login panel.
CVSS Score
7.5
EPSS Score
0.0
Published
2024-01-09
Incorrect access control in TP-Link Tapo before v3.1.315 allows attackers to access user credentials in plaintext.
CVSS Score
6.5
EPSS Score
0.0
Published
2023-12-28
An issue in TPLink Smart Bulb Tapo series L530 before 1.2.4, L510E before 1.1.0, L630 before 1.0.4, P100 before 1.5.0, and Tapo Application 2.8.14 allows a remote attacker to replay old messages encrypted with a still valid session key.
CVSS Score
7.5
EPSS Score
0.003
Published
2023-09-25
An issue in TPLink Smart Bulb Tapo series L530 before 1.2.4, L510E before 1.1.0, L630 before 1.0.4, P100 before 1.5.0, and Tapo Application 2.8.14 allows a remote attacker to obtain sensitive information via the TSKEP authentication function.
CVSS Score
6.5
EPSS Score
0.001
Published
2023-08-22
An issue in TPLink Smart Bulb Tapo series L530 before 1.2.4, L510E before 1.1.0, L630 before 1.0.4, P100 before 1.5.0, and Tapo Application 2.8.14 allows a remote attacker to obtain sensitive information via the IV component in the AES128-CBC function.
CVSS Score
6.5
EPSS Score
0.001
Published
2023-08-22
An issue in TPLink Smart Bulb Tapo series L530 1.1.9, L510E 1.0.8, L630 1.0.3, P100 1.4.9, Smart Camera Tapo series C200 1.1.18, and Tapo Application 2.8.14 allows a remote attacker to obtain sensitive information via the authentication code for the UDP message.
CVSS Score
6.5
EPSS Score
0.001
Published
2023-08-22


Contact Us

Shodan ® - All rights reserved