VYPR

Tapo P100

by TP-Link

CVEs (5)

  • CVE-2025-15557HigFeb 5, 2026
    risk 0.57cvss 8.8epss 0.00

    An Improper Certificate Validation vulnerability in TP-Link Tapo H100 v1 and Tapo P100 v1 allows an on-path attacker on the same network segment to intercept and modify encrypted device-cloud communications.  This may compromise the confidentiality and integrity of…

  • CVE-2023-38907HigSep 25, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue in TPLink Smart Bulb Tapo series L530 before 1.2.4, L510E before 1.1.0, L630 before 1.0.4, P100 before 1.5.0, and Tapo Application 2.8.14 allows a remote attacker to replay old messages encrypted with a still valid session key.

  • CVE-2023-38909MedAug 22, 2023
    risk 0.42cvss 6.5epss 0.01

    An issue in TPLink Smart Bulb Tapo series L530 before 1.2.4, L510E before 1.1.0, L630 before 1.0.4, P100 before 1.5.0, and Tapo Application 2.8.14 allows a remote attacker to obtain sensitive information via the IV component in the AES128-CBC function.

  • CVE-2023-38908MedAug 22, 2023
    risk 0.42cvss 6.5epss 0.01

    An issue in TPLink Smart Bulb Tapo series L530 before 1.2.4, L510E before 1.1.0, L630 before 1.0.4, P100 before 1.5.0, and Tapo Application 2.8.14 allows a remote attacker to obtain sensitive information via the TSKEP authentication function.

  • CVE-2023-38906MedAug 22, 2023
    risk 0.42cvss 6.5epss 0.00

    An issue in TPLink Smart Bulb Tapo series L530 1.1.9, L510E 1.0.8, L630 1.0.3, P100 1.4.9, Smart Camera Tapo series C200 1.1.18, and Tapo Application 2.8.14 allows a remote attacker to obtain sensitive information via the authentication code for the UDP message.