CVE-2026-3822

MEDIUM

Taipower APP - Improper Certificate Validation

Title source: llm
STIX 2.1

Description

Taipower APP for Andorid developed by Taipower has an Improper Certificate Validation vulnerability. When establishing an HTTPS connection with the server, the application fails to verify the server-side TLS/SSL certificate. This flaw allows an unauthenticated remote attackers to exploit the vulnerability to perform a Man-in-the-Middle (MITM) attack to read and tamper with network packets.

References (2)

Core 2
Core References
Various Sources third-party-advisory
https://www.twcert.org.tw/tw/cp-132-10750-3735f-1.html
Various Sources third-party-advisory
https://www.twcert.org.tw/en/cp-139-10751-23871-2.html

Scores

CVSS v3 6.5
EPSS 0.0015
EPSS Percentile 4.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-295
Status published
Products (1)
taipower/taipower_app < 3.4.4
Published Mar 09, 2026
Tracked Since Mar 09, 2026