Unauthenticated API Vulnerability in TP-Link Tapo C210 App for iOS and Android
CVE-2025-14553
7HIGH
What is CVE-2025-14553?
An unprotected API response in the TP-Link Tapo C210 app for both iOS and Android allows unauthorized disclosure of password hashes. This exposure can enable attackers within the same local network to exploit these hashes through brute force techniques. Users are advised to update their mobile applications to mitigate the risk of unauthorized access, while noting that device firmware does not address this specific issue.
Affected Version(s)
TP-Link Tapo App Android 0 < 3.1.6
TP-Link Tapo App iOS 0 < 3.1.601
References
CVSS V4
Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Juraj NyĂri
