7
/ 10
HIGH
CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
Description
Exposure of password hashes through an unauthenticated API response in TP-Link Tapo C210 V.1.8 app on iOS and Android, allowing attackers to brute force the password in the local network.Β Issue can be mitigated through mobile application updates. Device firmware remains unchanged.
Basic Information
ID
CVE-2025-14553
Source
TPLink
Published
Dec 16, 2025 at 18:38
Modified
Dec 16, 2025 at 19:10
Affected Product
Vendor
TP-Link Systems Inc.
Product
Tapo C210
Affected Versions
TP-Link Systems Inc. Tapo C210 0
TP-Link Systems Inc. Tapo C210 0
TP-Link Systems Inc. Tapo C210 0