Statement on Tapo privilege escalation on shared devices using notifications (CVE-2025-4975)
Vulnerability Description:
When a notification relating to low battery appears for a user with whom the device has been shared, tapping the notification grants full access to the power settings of that device.
Impact:
The low-priv user may change the power settings of the device.
CVSS v4.0 Score: 4.8 / Medium
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L
Affected Products/Versions and Fixes:
Affected Product Model |
Related Vulnerabilities |
Affected Version |
Fixed Version |
TP-Link Tapo app on Android |
CVE-2025-4975 |
< 3.10.513 |
3.10.513 or above |
Recommendations:
We strongly recommended that users with affected devices take the following actions:
- Download and update to the latest Android Tapo app to fix the vulnerability.
Disclaimer:
If you do not take all of the recommended actions, this vulnerability concern will remain. TP-Link cannot bear any responsibility for the consequences that could have been avoided by following the recommended actions in this statement.
Is this faq useful?
Your feedback helps improve this site.

TP-Link Community
Still need help? Search for answers, ask questions, and get help from TP-Link experts and other users around the world.