CVE-2025-8065

MEDIUM WAF: Medium
CVSS 6.5 Published: 2025-12-20
CWE-400

A buffer overflow vulnerability exists in the ONVIF XML parser of Tapo C200 V3. An unauthenticated attacker on the same local network segment can send specially crafted SOAP XML requests, causing memory overflow and device crash, resulting in denial-of-service (DoS).

WAF Coverage Analysis

Uncontrolled Resource Consumption Medium WAF Coverage

OWASP: A05:2021 Security Misconfiguration

912xxx - DOS Protection

Affected Software

VendorProductVersion
tp-linktapo_c200_firmware1.3.3
tp-linktapo_c200_firmware1.3.4
tp-linktapo_c200_firmware1.3.5
tp-linktapo_c200_firmware1.3.7
tp-linktapo_c200_firmware1.3.9
tp-linktapo_c200_firmware1.3.11
tp-linktapo_c200_firmware1.3.13
tp-linktapo_c200_firmware1.3.14
tp-linktapo_c200_firmware1.3.15
tp-linktapo_c200_firmware1.4.1

References

Back to CVE Database