The attacker may obtain root access by connecting to the UART port and this vulnerability requires the attacker to have the physical access to the device.
This issue affects Tapo D230S1 V1.20: before 1.2.2 Build 20250907.
CVSS
No CVSS.
References
| Link | Resource |
|---|---|
| https://www.tp-link.com/en/support/faq/4693/ |
Configurations
No configuration.
History
No history.
Information
Published : 2025-09-30 11:37
Updated : 2025-10-02 19:12
NVD link : CVE-2025-10991
Mitre link : CVE-2025-10991
CVE.ORG link : CVE-2025-10991
JSON object : View
Products Affected
No product.
CWE
CWE-306
Missing Authentication for Critical Function
