216.73.217.22

CVE-2025-15557

· Published 05/02/2026 18:16 · Modified 05/02/2026 20:47

Labels: CVE-2025-15557 2026-02-05CVE-2025-15557CWE-295f23511db-6c3e-4e32-a477-6aa17d310630

Essential information

Published
05/02/2026 18:16
Modified
05/02/2026 20:47
Author
Creator
CVSS
7.5 HIGH (v3) 7.5 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

An Improper Certificate Validation vulnerability in TP-Link Tapo H100 v1 and Tapo P100 v1 allows an on-path attacker on the same network segment to intercept and modify encrypted device-cloud communications.  This may compromise the confidentiality and integrity of device-to-cloud communication, enabling manipulation of device data or operations.

NVD status

Status
Undergoing Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
f23511db-6c3e-4e32-a477-6aa17d310630
NVD
View on NVD

Affected products (CPE)

ProductCPE
tp-link / tapo h100 cpe:2.3:a:tp-link:tapo_h100:v1:*:*:*:*:*:*:*
tp-link / tapo p100 cpe:2.3:a:tp-link:tapo_p100:v1:*:*:*:*:*:*:*

References