Taipower APP developed by Taipower has an Improper Certificate Validation vulnerability. When establishing an HTTPS connection with the server, the application fails to verify the server-side TLS/SSL certificate. This flaw allows an unauthenticated remote attackers to exploit the vulnerability to perform a Man-in-the-Middle (MITM) attack to read and tamper with network packets.

Project Subscriptions

Vendors Products
Taipower Subscribe
Taipower App Subscribe
Advisories

No advisories yet.

Fixes

Solution

Please update to version 3.4.5 or later.


Workaround

No workaround given by the vendor.

History

Mon, 09 Mar 2026 04:15:00 +0000

Type Values Removed Values Added
Description Taipower APP developed by Taipower has an Improper Certificate Validation vulnerability. When establishing an HTTPS connection with the server, the application fails to verify the server-side TLS/SSL certificate. This flaw allows an unauthenticated remote attackers to exploit the vulnerability to perform a Man-in-the-Middle (MITM) attack to read and tamper with network packets.
Title Taipower|Taipower APP - Improper Certificate Validation
First Time appeared Taipower
Taipower taipower App
Weaknesses CWE-295
CPEs cpe:2.3:a:taipower:taipower_app:*:*:*:*:*:*:*:*
Vendors & Products Taipower
Taipower taipower App
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N'}

cvssV4_0

{'score': 8.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published:

Updated: 2026-03-09T05:59:33.384Z

Reserved: 2026-03-09T03:01:54.726Z

Link: CVE-2026-3822

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-03-09T04:16:10.173

Modified: 2026-03-09T04:16:10.173

Link: CVE-2026-3822

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses