CVE-2025-15542

MEDIUM

TP-Link VX800v Firmware < 800.0.12 - Denial of Service via SIP INVITE Flood

Title source: llm
STIX 2.1

Description

Improper handling of exceptional conditions in VX800v v1.0 in SIP processing allows an attacker to flood the device with crafted INVITE messages, blocking all voice lines and causing a denial of service on incoming calls.

References (2)

Core 2
Core References
Various Sources vendor-advisory
https://www.tp-link.com/us/support/faq/4930/

Scores

CVSS v3 5.3
EPSS 0.0025
EPSS Percentile 16.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-754
Status published
Products (1)
tp-link/vx800v_firmware < 800.0.12
Published Jan 29, 2026
Tracked Since Feb 18, 2026