A
buffer overflow vulnerability exists in the ONVIF XML parser of Tapo C200 V3. An unauthenticated attacker on the same local network segment can send specially crafted SOAP XML requests, causing memory overflow and device crash, resulting in denial-of-service (DoS).
References
| Link | Resource |
|---|---|
| https://www.tp-link.com/us/support/download/tapo-c200/v3/#Firmware-Release-Notes | Release Notes |
| https://www.tp-link.com/us/support/faq/4849/ | Vendor Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
History
08 Jan 2026, 19:38
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Tp-link tapo C200
Tp-link Tp-link tapo C200 Firmware |
|
| CPE | cpe:2.3:o:tp-link:tapo_c200_firmware:1.3.7:build_230920:*:*:*:*:*:* cpe:2.3:o:tp-link:tapo_c200_firmware:1.3.11:build_231115:*:*:*:*:*:* cpe:2.3:o:tp-link:tapo_c200_firmware:1.3.15:build_240715:*:*:*:*:*:* cpe:2.3:o:tp-link:tapo_c200_firmware:1.4.1:build_241212:*:*:*:*:*:* cpe:2.3:o:tp-link:tapo_c200_firmware:1.4.2:build_250313:*:*:*:*:*:* cpe:2.3:o:tp-link:tapo_c200_firmware:1.4.4:build_250922:*:*:*:*:*:* cpe:2.3:o:tp-link:tapo_c200_firmware:1.3.4:build_230424:*:*:*:*:*:* cpe:2.3:o:tp-link:tapo_c200_firmware:1.3.14:build_240513:*:*:*:*:*:* cpe:2.3:o:tp-link:tapo_c200_firmware:1.3.13:build_240327:*:*:*:*:*:* cpe:2.3:o:tp-link:tapo_c200_firmware:1.3.5:build_230717:*:*:*:*:*:* cpe:2.3:o:tp-link:tapo_c200_firmware:1.3.3:build_230228:*:*:*:*:*:* cpe:2.3:o:tp-link:tapo_c200_firmware:1.3.9:build_231019:*:*:*:*:*:* cpe:2.3:h:tp-link:tapo_c200:3:*:*:*:*:*:*:* |
|
| References | () https://www.tp-link.com/us/support/download/tapo-c200/v3/#Firmware-Release-Notes - Release Notes | |
| References | () https://www.tp-link.com/us/support/faq/4849/ - Vendor Advisory | |
| CWE | CWE-120 | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
20 Dec 2025, 01:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-20 01:16
Updated : 2026-01-08 19:38
NVD link : CVE-2025-8065
Mitre link : CVE-2025-8065
CVE.ORG link : CVE-2025-8065
JSON object : View
Products Affected