CVE-2025-10991

Severity CVSS v4.0:
HIGH
Type:
CWE-306 Missing Authentication for Critical Function
Publication date:
30/09/2025
Last modified:
02/10/2025

Description

The attacker may obtain root access by connecting to the UART port and this vulnerability requires the attacker to have the physical access to the device.<br /> <br /> This issue affects Tapo D230S1 V1.20: before 1.2.2 Build 20250907.

References to Advisories, Solutions, and Tools