CVE-2025-8627

Severity CVSS v4.0:
HIGH
Type:
CWE-306 Missing Authentication for Critical Function
Publication date:
25/08/2025
Last modified:
15/09/2025

Description

The TP-Link KP303 Smartplug can be issued unauthenticated protocol commands that may cause unintended power-off condition and potential information leak.<br /> <br /> This issue affects TP-Link KP303 (US) Smartplug: before 1.1.0.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:tp-link:kp303_firmware:*:*:*:*:*:*:*:* 1.1.0 (excluding)
cpe:2.3:h:tp-link:kp303:2.0:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools