CVE-2026-3822

Severity CVSS v4.0:
HIGH
Type:
CWE-295 Improper Certificate Validation
Publication date:
09/03/2026
Last modified:
10/03/2026

Description

Taipower APP developed by Taipower has an Improper Certificate Validation vulnerability. When establishing an HTTPS connection with the server, the application fails to verify the server-side TLS/SSL certificate. This flaw allows an unauthenticated remote attackers to exploit the vulnerability to perform a Man-in-the-Middle (MITM) attack to read and tamper with network packets.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:taipower:taipower_app:*:*:*:*:*:*:*:* 3.4.4 (including)