CVE-2025-15548

Some VX800v v1.0 web interface endpoints transmit sensitive information over unencrypted HTTP due to missing application layer encryption, allowing a network adjacent attacker to intercept this traffic and compromise its confidentiality.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:tp-link:vx800v_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:vx800v:1.0:*:*:*:*:*:*:*

History

09 Mar 2026, 17:52

Type Values Removed Values Added
First Time Tp-link
Tp-link vx800v Firmware
Tp-link vx800v
Summary
  • (es) Algunos puntos finales de la interfaz web VX800v v1.0 transmiten información sensible a través de HTTP sin cifrar debido a la falta de cifrado en la capa de aplicación, lo que permite a un atacante adyacente a la red interceptar este tráfico y comprometer su confidencialidad.
CPE cpe:2.3:o:tp-link:vx800v_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:vx800v:1.0:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
References () https://www.tp-link.com/de/support/download/vx800v/#Firmware - () https://www.tp-link.com/de/support/download/vx800v/#Firmware - Product
References () https://www.tp-link.com/us/support/faq/4930/ - () https://www.tp-link.com/us/support/faq/4930/ - Vendor Advisory

29 Jan 2026, 19:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-29 19:16

Updated : 2026-03-09 17:52


NVD link : CVE-2025-15548

Mitre link : CVE-2025-15548

CVE.ORG link : CVE-2025-15548


JSON object : View

Products Affected

tp-link

  • vx800v
  • vx800v_firmware
CWE
CWE-311

Missing Encryption of Sensitive Data