VendorsTP-Linktapoall versions
Vulnerabilities

TP-Link TAPO

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

8CVEs
CVE-2025-9293
Insufficient Certificate Validation in Multiple Mobile Applications Allows Man in the Middle Interception
Published 2026-02-13 · Analyzed
8.1EPSS 0.002
CVE-2023-38907
An issue in TPLink Smart Bulb Tapo series L530 before 1.2.4, L510E before 1.1.0, L630 before 1.0.4, P100 before 1.5.0, and Tapo Application 2.8.14 allows a remote attacker to replay old messages encrypted with a still valid session key.
Published 2023-09-25 · Modified
7.5EPSS 0.007
CVE-2023-27098
TP-Link Tapo APK up to v2.12.703 uses hardcoded credentials for access to the login panel.
Published 2024-01-09 · Modified
7.5EPSS 0.004
CVE-2025-9292
Permissive Web Security Policy Allows Cross-Origin Access Control Bypass on Omada Cloud Controllers
Published 2026-02-13 · Analyzed
7.5EPSS 0.004
CVE-2023-38909
An issue in TPLink Smart Bulb Tapo series L530 before 1.2.4, L510E before 1.1.0, L630 before 1.0.4, P100 before 1.5.0, and Tapo Application 2.8.14 allows a remote attacker to obtain sensitive information via the IV component in the AES128-CBC function.
Published 2023-08-22 · Modified
6.5EPSS 0.008
CVE-2023-38908
An issue in TPLink Smart Bulb Tapo series L530 before 1.2.4, L510E before 1.1.0, L630 before 1.0.4, P100 before 1.5.0, and Tapo Application 2.8.14 allows a remote attacker to obtain sensitive information via the TSKEP authentication function.
Published 2023-08-22 · Modified
6.5EPSS 0.005
CVE-2023-38906
An issue in TPLink Smart Bulb Tapo series L530 1.1.9, L510E 1.0.8, L630 1.0.3, P100 1.4.9, Smart Camera Tapo series C200 1.1.18, and Tapo Application 2.8.14 allows a remote attacker to obtain sensitive information via the authentication code for the UDP message.
Published 2023-08-21 · Modified
6.5EPSS 0.005
CVE-2023-34829
Incorrect access control in TP-Link Tapo before v3.1.315 allows attackers to access user credentials in plaintext.
Published 2023-12-28 · Modified
6.5EPSS 0.002