Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-38mv-4mrh-vpwc

Опубликовано: 20 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 8.7
CVSS3: 8.1

Описание

The HTTPS service on Tapo C200 V3 exposes a connectAP interface without proper authentication. An unauthenticated attacker on the same local network segment can exploit this to modify the device’s Wi-Fi configuration, resulting in loss of connectivity and denial-of-service (DoS).

The HTTPS service on Tapo C200 V3 exposes a connectAP interface without proper authentication. An unauthenticated attacker on the same local network segment can exploit this to modify the device’s Wi-Fi configuration, resulting in loss of connectivity and denial-of-service (DoS).

EPSS

Процентиль: 27%
0.00097
Низкий

8.7 High

CVSS4

8.1 High

CVSS3

Дефекты

CWE-306

Связанные уязвимости

CVSS3: 8.1
nvd
около 2 месяцев назад

The HTTPS service on Tapo C200 V3 exposes a connectAP interface without proper authentication. An unauthenticated attacker on the same local network segment can exploit this to modify the device’s Wi-Fi configuration, resulting in loss of connectivity and denial-of-service (DoS).

EPSS

Процентиль: 27%
0.00097
Низкий

8.7 High

CVSS4

8.1 High

CVSS3

Дефекты

CWE-306