Some VX800v v1.0 web interface endpoints transmit sensitive information over unencrypted HTTP due to missing application layer encryption, allowing a network adjacent attacker to intercept this traffic and compromise its confidentiality.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 29 Jan 2026 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 29 Jan 2026 18:30:00 +0000

Type Values Removed Values Added
Description Some VX800v v1.0 web interface endpoints transmit sensitive information over unencrypted HTTP due to missing application layer encryption, allowing a network adjacent attacker to intercept this traffic and compromise its confidentiality.
Title Missing Application-Layer Encryption in Web Interface Endpoints on TP-Link VX800v
Weaknesses CWE-311
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: TPLink

Published:

Updated: 2026-01-29T18:46:49.264Z

Reserved: 2026-01-26T21:21:46.364Z

Link: CVE-2025-15548

cve-icon Vulnrichment

Updated: 2026-01-29T18:46:44.513Z

cve-icon NVD

Status : Received

Published: 2026-01-29T19:16:11.663

Modified: 2026-01-29T19:16:11.663

Link: CVE-2025-15548

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses