Statement on Tapo privilege escalation on shared devices using notifications (CVE-2025-4975)

Security Advisory
Updated 05-22-2025 20:37:18 PM Number of views for this article1358

CVE-2025-4975

Vulnerability Description:

When a notification relating to low battery appears for a user with whom the device has been shared, tapping the notification grants full access to the power settings of that device.

Impact:

The low-priv user may change the power settings of the device.

CVSS v4.0 Score: 4.8 / Medium

CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L

Affected Products/Versions and Fixes:

Affected Product Model

Related Vulnerabilities

Affected Version

Fixed Version

TP-Link Tapo app on Android

CVE-2025-4975

< 3.10.513

3.10.513 or above

Recommendations:

We strongly recommended that users with affected devices take the following actions:

- Download and update to the latest Android Tapo app to fix the vulnerability.

Disclaimer:

If you do not take all of the recommended actions, this vulnerability concern will remain. TP-Link cannot bear any responsibility for the consequences that could have been avoided by following the recommended actions in this statement.

Is this faq useful?

Your feedback helps improve this site.

Community

TP-Link Community

Still need help? Search for answers, ask questions, and get help from TP-Link experts and other users around the world.

Visit the Community >