CVE-2025-15548: TP-Link VX800V Firmware

Medium severity, CVSS 6.5. EPSS: 0.1% chance of exploitation in the next 30 days.

Some VX800v v1.0 web interface endpoints transmit sensitive information over unencrypted HTTP due to missing application layer encryption, allowing a network adjacent attacker to intercept this traffic and compromise its confidentiality.

Affected products

  • TP-Link VX800V Firmware: before 800.0.18 (fixed in 800.0.18)

Published 2026-01-29. Last modified 2026-06-17.