CVE 7 HIGH

Password Hash Leak Could Lead to Unauthorized Access on Tapo 210 via Local Network_CVE-2025-14553

7 / 10
HIGH
CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N

Description

Exposure of password hashes through an unauthenticated API response in TP-Link Tapo C210 V.1.8 app on iOS and Android, allowing attackers to brute force the password in the local network.Β Issue can be mitigated through mobile application updates. Device firmware remains unchanged.

Basic Information

ID CVE-2025-14553
Source TPLink
Published Dec 16, 2025 at 18:38
Modified Dec 16, 2025 at 19:10

Affected Product

Vendor TP-Link Systems Inc.
Product Tapo C210
Affected Versions TP-Link Systems Inc. Tapo C210 0
TP-Link Systems Inc. Tapo C210 0

CWE Classification

References

πŸ’­ Join the Security Discussion

πŸ”’ Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.