VYPR
Unrated severityNVD Advisory· Published Aug 25, 2025· Updated Aug 26, 2025

Unauthenticated Protocol Commands on TP-Link KP303

CVE-2025-8627

Description

The TP-Link KP303 Smartplug can be issued unauthenticated protocol commands that may cause unintended power-off condition and potential information leak.

This issue affects TP-Link KP303 (US) Smartplug: before 1.1.0.

Affected products

2
  • TP-Link/KP303llm-create
    Range: <1.1.0
  • TP-Link Systems Inc./TP-Link KP303 (US) Smartplugv5
    Range: 0

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.