CVEs (8)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Tp Link 14Aginet DecoFesta+11 moreJun 17, 2026 Feb 13, 2026 7.7 HIGH· v4 8.1 HIGH· v3 N/A· v2 A vulnerability in the certificate validation logic may allow applications to accept untrusted or improperly validated server identities during TLS communication. An attacker in a privileged network position may be able...Show more |
1Tp Link 14Aginet DecoFesta+11 moreJun 17, 2026 Feb 13, 2026 2.0 LOW· v4 7.5 HIGH· v3 N/A· v2 A permissive web security configuration may allow cross-origin restrictions enforced by modern browsers to be bypassed under specific circumstances. Exploitation requires the presence of an existing client-side injectio...Show more |
TP-Link Tapo APK up to v2.12.703 uses hardcoded credentials for access to the login panel. |
Incorrect access control in TP-Link Tapo before v3.1.315 allows attackers to access user credentials in plaintext. |
An issue in TPLink Smart Bulb Tapo series L530 before 1.2.4, L510E before 1.1.0, L630 before 1.0.4, P100 before 1.5.0, and Tapo Application 2.8.14 allows a remote attacker to replay old messages encrypted with a still va...Show more |
An issue in TPLink Smart Bulb Tapo series L530 before 1.2.4, L510E before 1.1.0, L630 before 1.0.4, P100 before 1.5.0, and Tapo Application 2.8.14 allows a remote attacker to obtain sensitive information via the IV compo...Show more |
An issue in TPLink Smart Bulb Tapo series L530 before 1.2.4, L510E before 1.1.0, L630 before 1.0.4, P100 before 1.5.0, and Tapo Application 2.8.14 allows a remote attacker to obtain sensitive information via the TSKEP au...Show more |
An issue in TPLink Smart Bulb Tapo series L530 1.1.9, L510E 1.0.8, L630 1.0.3, P100 1.4.9, Smart Camera Tapo series C200 1.1.18, and Tapo Application 2.8.14 allows a remote attacker to obtain sensitive information via th...Show more |