TP-Link VX800v Missing Application-Layer Encryption Vulnerability
Vulnerability
A vulnerability exists in the TP-Link VX800v version 1.0 web interface, where certain endpoints transmit sensitive information over unencrypted HTTP. This lack of application layer encryption allows a network-adjacent attacker to intercept the traffic and compromise its confidentiality.
Impact
Exploitation of this vulnerability could lead to unauthorized interception of sensitive information, allowing an attacker to access confidential data transmitted over the affected web interface endpoints.
Remediation
Users are advised to update to the latest firmware version. The latest firmware for the VX800v can be downloaded from the TP-Link support page for this product.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
