Aller au contenu

Fiche vulnérabilité

CVE-2026-3822 : faille moyenne taipower taipower app (CVSS 4.8)

Description

Taipower APP for Andorid developed by Taipower has an Improper Certificate Validation vulnerability. When establishing an HTTPS connection with the server, the application fails to verify the server-side TLS/SSL certificate. This flaw allows an unauthenticated remote attackers to exploit the vulnerability to perform a Man-in-the-Middle (MITM) attack to read and tamper with network packets.

En bref

Sévérité
Moyenne (CVSS 4.8)
Vecteur CVSS
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
Exploitation active
Non signalée par la CISA
Publication
9 mars 2026
Dernière mise à jour
17 juin 2026

Produits concernés

  • taipower taipower app

Références

Rechercher une autre vulnérabilité dans la base CVE