CVE-2025-15548

Some VX800v v1.0 web interface endpoints transmit sensitive information over unencrypted HTTP due to missing application layer encryption, allowing a network adjacent attacker to intercept this traffic and compromise its confidentiality.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:tp-link:vx800v_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:vx800v:1.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-01-29 19:16

Updated : 2026-03-09 17:52


NVD link : CVE-2025-15548

Mitre link : CVE-2025-15548

CVE.ORG link : CVE-2025-15548


JSON object : View

Products Affected

tp-link

  • vx800v
  • vx800v_firmware
CWE
CWE-311

Missing Encryption of Sensitive Data