CVE-2025-15557
EUVD-2025-20682405.02.2026, 18:16
An Improper Certificate Validation vulnerability in TP-Link Tapo H100 v1 and Tapo P100 v1 allows an on-path attacker on the same network segment to intercept and modify encrypted device-cloud communications. This may compromise the confidentiality and integrity of device-to-cloud communication, enabling manipulation of device data or operations.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| tp-link | tapo_h100_firmware | 𝑥 < 1.6.1 |
| tp-link | tapo_p100_firmware | 𝑥 < 1.2.6 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration