Incorrect access control in TP-Link Tapo before v3.1.315 allows attackers to access user credentials in plaintext.
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Tapo | Tp-link | * | 3.1.315 (excluding) |