Insufficient Certificate Validation in Multiple Mobile Applications Allows Man in the Middle Interception
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.7epss 0.2%
exploitation probability
0.2%top 87% of all CVEs
observed exploitation
nono source reports it
A vulnerability in the certificate validation logic may allow applications to accept untrusted or improperly validated server identities during TLS communication. An attacker in a privileged network position may be able to intercept or modify traffic if they can position themselves within the communication channel. Successful exploitation may compromise confidentiality, integrity, and availability of application data.
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:L/SI:N/SA:N
Affected products
TP Link Systems Inc. · Omada AppTP-Link Systems Inc. · Aginet AppTP-Link Systems Inc. · Deco AppTP-Link Systems Inc. · Festa AppTP-Link Systems Inc. · Kasa AppTP-Link Systems Inc. · KidShieldTP-Link Systems Inc. · Omada GuardTP-Link Systems Inc. · Tapo AppTP-Link Systems Inc. · Tether AppTP-Link Systems Inc. · tpCamera AppTP-Link Systems Inc. · TP-Partner AppTP-Link Systems Inc. · VIGI AppTP-Link Systems Inc. · Wi-Fi NaviTP-Link Systems Inc. · WiFi Toolkit