CVE-2025-15557: TP-Link Tapo h100 Firmware

High severity, CVSS 8.8. EPSS: 0.2% chance of exploitation in the next 30 days.

An Improper Certificate Validation vulnerability in TP-Link Tapo H100 v1 and Tapo P100 v1 allows an on-path attacker on the same network segment to intercept and modify encrypted device-cloud communications.  This may compromise the confidentiality and integrity of device-to-cloud communication, enabling manipulation of device data or operations.

Affected products

  • TP-Link Tapo h100 Firmware: before 1.6.1 (fixed in 1.6.1)
  • TP-Link Tapo p100 Firmware: before 1.2.6 (fixed in 1.2.6)

Published 2026-02-05. Last modified 2026-06-17.