CVE-2025-8065
MEDIUM WAF: Medium
CVSS 6.5
Published: 2025-12-20
CWE-400
A buffer overflow vulnerability exists in the ONVIF XML parser of Tapo C200 V3. An unauthenticated attacker on the same local network segment can send specially crafted SOAP XML requests, causing memory overflow and device crash, resulting in denial-of-service (DoS).
WAF Coverage Analysis
Uncontrolled Resource Consumption
Medium WAF Coverage
OWASP: A05:2021 Security Misconfiguration
912xxx - DOS Protection
Affected Software
| Vendor | Product | Version |
|---|---|---|
| tp-link | tapo_c200_firmware | 1.3.3 |
| tp-link | tapo_c200_firmware | 1.3.4 |
| tp-link | tapo_c200_firmware | 1.3.5 |
| tp-link | tapo_c200_firmware | 1.3.7 |
| tp-link | tapo_c200_firmware | 1.3.9 |
| tp-link | tapo_c200_firmware | 1.3.11 |
| tp-link | tapo_c200_firmware | 1.3.13 |
| tp-link | tapo_c200_firmware | 1.3.14 |
| tp-link | tapo_c200_firmware | 1.3.15 |
| tp-link | tapo_c200_firmware | 1.4.1 |
References
- www.tp-link.com (Release Notes)
- www.tp-link.com (Vendor Advisory)