CVE-2025-4975 MEDIUM

CVE-2025-4975: Tapo privilege escalation on shared devices using notifications

Vendor Tp-Link Systems Inc.
Product TP-Link Tapo app
Weakness CWE-863 · Incorrect authorization
Published May 22, 2025
Last update October 8, 2025

CVSS base score

4.8/10
Attack vector Local
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L

What the vulnerability does

01Description

When a notification relating to low battery appears for a user with whom the device has been shared, tapping the notification grants full access to the power settings of that device.

Key dates

02Disclosure timeline

May 22, 2025 CVE published
October 8, 2025 Record updated