The attacker may obtain root access by connecting to the UART port and this vulnerability requires the attacker to have the physical access to the device.
This issue affects Tapo D230S1 V1.20: before 1.2.2 Build 20250907.
CVSS
No CVSS.
References
Link | Resource |
---|---|
https://www.tp-link.com/en/support/faq/4693/ |
Configurations
No configuration.
History
30 Sep 2025, 14:15
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-306 |
30 Sep 2025, 11:37
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-09-30 11:37
Updated : 2025-10-02 19:12
NVD link : CVE-2025-10991
Mitre link : CVE-2025-10991
CVE.ORG link : CVE-2025-10991
JSON object : View
Products Affected
No product.
CWE
CWE-306
Missing Authentication for Critical Function