CVE-2026-3822

Taipower APP for Andorid developed by Taipower has an Improper Certificate Validation vulnerability. When establishing an HTTPS connection with the server, the application fails to verify the server-side TLS/SSL certificate. This flaw allows an unauthenticated remote attackers to exploit the vulnerability to perform a Man-in-the-Middle (MITM) attack to read and tamper with network packets.
Configurations

Configuration 1 (hide)

cpe:2.3:a:taipower:taipower_app:*:*:*:*:*:*:*:*

History

11 Mar 2026, 07:16

Type Values Removed Values Added
Summary (en) Taipower APP developed by Taipower has an Improper Certificate Validation vulnerability. When establishing an HTTPS connection with the server, the application fails to verify the server-side TLS/SSL certificate. This flaw allows an unauthenticated remote attackers to exploit the vulnerability to perform a Man-in-the-Middle (MITM) attack to read and tamper with network packets. (en) Taipower APP for Andorid developed by Taipower has an Improper Certificate Validation vulnerability. When establishing an HTTPS connection with the server, the application fails to verify the server-side TLS/SSL certificate. This flaw allows an unauthenticated remote attackers to exploit the vulnerability to perform a Man-in-the-Middle (MITM) attack to read and tamper with network packets.

10 Mar 2026, 18:47

Type Values Removed Values Added
First Time Taipower
Taipower taipower App
Summary
  • (es) La aplicación Taipower, desarrollada por Taipower, tiene una vulnerabilidad de Validación de Certificado Inadecuada. Al establecer una conexión HTTPS con el servidor, la aplicación no verifica el certificado TLS/SSL del lado del servidor. Este fallo permite a atacantes remotos no autenticados explotar la vulnerabilidad para realizar un ataque man-in-the-middle (MitM) para leer y manipular paquetes de red.
CPE cpe:2.3:a:taipower:taipower_app:*:*:*:*:*:*:*:*
References () https://www.twcert.org.tw/en/cp-139-10751-23871-2.html - () https://www.twcert.org.tw/en/cp-139-10751-23871-2.html - Third Party Advisory
References () https://www.twcert.org.tw/tw/cp-132-10750-3735f-1.html - () https://www.twcert.org.tw/tw/cp-132-10750-3735f-1.html - Third Party Advisory

09 Mar 2026, 04:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-09 04:16

Updated : 2026-03-11 07:16


NVD link : CVE-2026-3822

Mitre link : CVE-2026-3822

CVE.ORG link : CVE-2026-3822


JSON object : View

Products Affected

taipower

  • taipower_app
CWE
CWE-295

Improper Certificate Validation