CVE-2025-15557 Details
Description
An Improper Certificate Validation vulnerability in TP-Link Tapo H100 v1 and Tapo P100 v1 allows an on-path attacker on the same network segment to intercept and modify encrypted device-cloud communications. This may compromise the confidentiality and integrity of device-to-cloud communication, enabling manipulation of device data or operations.
A vulnerability allowing improper certificate validation has been identified in the TP-Link Tapo H100 v1 and Tapo P100 v1. This vulnerability allows an on-path attacker on the same network segment to intercept and modify encrypted communications between the devices and the cloud. As a result, the confidentiality and integrity of the data exchanged can be compromised, potentially leading to unauthorized manipulation of device information or control.
Users are advised to update to the latest firmware version. Instructions for downloading the updated firmware are available on the TP-Link support pages for both the Tapo H100 and Tapo P100.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 5, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.tp-link.com/en/support/download/tapo-h100/ | TPLink | Product |
| https://www.tp-link.com/en/support/download/tapo-p100/ | TPLink | Product |
| https://www.tp-link.com/us/support/download/tapo-h100/ | TPLink | Product |
| https://www.tp-link.com/us/support/download/tapo-p100/ | TPLink | Product |
| https://www.tp-link.com/us/support/faq/4949/ | TPLink | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-295 | Improper Certificate Validation | TPLink |
Affected Products
| Product | Versions |
|---|---|
| tp-link tapo h100 firmware | < 1.6.1 |
CPE
Remediation
| |
| tp-link tapo h100 | 1.0 |
CPE
Remediation
| |
| tp-link tapo p100 firmware | < 1.2.6 |
CPE
Remediation
| |
| tp-link tapo p100 | 1.0 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | TPLink |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 12, 2026 | Initial Analysis | [email protected] |
| Feb 5, 2026 | New CVE Received | TPLink |