7
/ 10
HIGH
CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Description
The attacker may obtain root access by connecting to the UART port and this vulnerability requires the attacker to have the physical access to the device.
This issue affects Tapo D230S1 V1.20: before 1.2.2 Build 20250907.
This issue affects Tapo D230S1 V1.20: before 1.2.2 Build 20250907.
Basic Information
ID
CVE-2025-10991
Source
TPLink
Published
Sep 30, 2025 at 00:08
Affected Product
Vendor
TP-Link Systems Inc.
Product
Tapo D230S1 V1.20
Affected Versions
TP-Link Systems Inc. Tapo D230S1 V1.20 0