VendorsTP-Linktapoany version
Vulnerabilities

TP-Link TAPO any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2025-9293
Insufficient Certificate Validation in Multiple Mobile Applications Allows Man in the Middle Interception
Published 2026-02-13 · Analyzed
8.1EPSS 0.002
CVE-2023-27098
TP-Link Tapo APK up to v2.12.703 uses hardcoded credentials for access to the login panel.
Published 2024-01-09 · Modified
7.5EPSS 0.004
CVE-2025-9292
Permissive Web Security Policy Allows Cross-Origin Access Control Bypass on Omada Cloud Controllers
Published 2026-02-13 · Analyzed
7.5EPSS 0.004
CVE-2023-34829
Incorrect access control in TP-Link Tapo before v3.1.315 allows attackers to access user credentials in plaintext.
Published 2023-12-28 · Modified
6.5EPSS 0.002