Tapo
Vendor:
First CVE: Aug 22, 2023 · Active for 2 years
8
Total CVEs
More Total CVEs than 85% of tracked products
2.7
Avg CVEs / Year
Higher CVE frequency than 75% of tracked products
7.1
Avg CVSS
Higher Avg CVSS than 42% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Tapo over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 22, 2023
2 years ago
Most Recent CVE
Feb 13, 2026
162 days ago
CVE Severity & Scoring
Tapo8 CVEs
50%
50%
All CVEs352,708 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network4 (50.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network4 (50.0%)
Attack Complexity
Low7 (87.5%)
High1 (12.5%)
Unknown0 (0.0%)
User Interaction
None8 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None8 (100.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-9292HIGH A permissive web security configuration may allow cross-origin restrictions enforced by modern browsers to be bypassed under specific circumstances. Exploitation requires the pres | Feb 13, 2026 | 7.5 | 29 | NO | NO |
CVE-2025-9293HIGH A vulnerability in the certificate validation logic may allow applications to accept untrusted or improperly validated server identities during TLS communication. An attacker in a | Feb 13, 2026 | 8.1 | 26 | NO | NO |
CVE-2023-27098HIGH TP-Link Tapo APK up to v2.12.703 uses hardcoded credentials for access to the login panel. | Jan 9, 2024 | 7.5 | 24 | NO | NO |
CVE-2023-38907HIGH An issue in TPLink Smart Bulb Tapo series L530 before 1.2.4, L510E before 1.1.0, L630 before 1.0.4, P100 before 1.5.0, and Tapo Application 2.8.14 allows a remote attacker to repla | Sep 25, 2023 | 7.5 | 21 | NO | NO |
CVE-2023-38909MEDIUM An issue in TPLink Smart Bulb Tapo series L530 before 1.2.4, L510E before 1.1.0, L630 before 1.0.4, P100 before 1.5.0, and Tapo Application 2.8.14 allows a remote attacker to obtai | Aug 22, 2023 | 6.5 | 19 | NO | NO |
CVE-2023-38906MEDIUM An issue in TPLink Smart Bulb Tapo series L530 1.1.9, L510E 1.0.8, L630 1.0.3, P100 1.4.9, Smart Camera Tapo series C200 1.1.18, and Tapo Application 2.8.14 allows a remote attacke | Aug 22, 2023 | 6.5 | 19 | NO | NO |
CVE-2023-38908MEDIUM An issue in TPLink Smart Bulb Tapo series L530 before 1.2.4, L510E before 1.1.0, L630 before 1.0.4, P100 before 1.5.0, and Tapo Application 2.8.14 allows a remote attacker to obtai | Aug 22, 2023 | 6.5 | 18 | NO | NO |
CVE-2023-34829MEDIUM Incorrect access control in TP-Link Tapo before v3.1.315 allows attackers to access user credentials in plaintext. | Dec 28, 2023 | 6.5 | 17 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (8 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (8 CVEs).
Media Mentions
Signals from CVEs in this product scope (8 CVEs).
Top CNAs Publishing CVEs For Tapo
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.8.14 | 4 | 6.8 | 0.6% | 0 | 0 |