CVE-2025-8627: TP-Link KP303 Firmware
High severity, CVSS 8.8. EPSS: 0.3% chance of exploitation in the next 30 days.
The TP-Link KP303 Smartplug can be issued unauthenticated protocol commands that may cause unintended power-off condition and potential information leak. This issue affects TP-Link KP303 (US) Smartplug: before 1.1.0.
Affected products
- TP-Link KP303 Firmware: before 1.1.0 (fixed in 1.1.0)
Published 2025-08-25. Last modified 2026-06-17.