Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-28314 | When a notification relating to low battery appears for a user with whom the device has been shared, tapping the notification grants full access to the power settings of that device. |
Wed, 08 Oct 2025 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-269 |
Wed, 08 Oct 2025 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-863 |
Fri, 23 May 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 22 May 2025 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | When a notification relating to low battery appears for a user with whom the device has been shared, tapping the notification grants full access to the power settings of that device. | |
| Title | Tapo privilege escalation on shared devices using notifications | |
| Weaknesses | CWE-269 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: TPLink
Published:
Updated: 2025-10-08T09:37:20.297Z
Reserved: 2025-05-20T02:56:36.381Z
Link: CVE-2025-4975
Updated: 2025-05-23T14:27:35.464Z
Status : Deferred
Published: 2025-05-22T22:15:31.043
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-4975
No data.
OpenCVE Enrichment
No data.
EUVD