- Description
- A stack-based buffer overflow vulnerability was identified in the ONVIF SOAP XML Parser in Tapo C200 v3 and C520WS v2.6. When processing XML tags with namespace prefixes, the parser fails to validate the prefix length before copying it to a fixed-size stack buffer. It allowed a crafted SOAP request with an oversized namespace prefix to cause memory corruption in stack. An unauthenticated attacker on the same local network may exploit this flaw to enable remote code execution with elevated privileges, leading to full compromise of the device.
- Source
- f23511db-6c3e-4e32-a477-6aa17d310630
- NVD status
- Modified
- Products
- tapo_c200_firmware
CVSS 4.0
- Type
- Secondary
- Base score
- 8.7
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- HIGH
CVSS 3.1
- Type
- Primary
- Base score
- 6.5
- Impact score
- 3.6
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Severity
- MEDIUM
- Hype score
- Not currently trending
๐ข ๐๐๐-๐๐๐๐-๐๐๐๐: ๐๐-๐๐ข๐ง๐ค ๐๐๐๐๐ ๐ฌ๐ญ๐๐๐ค ๐๐ฎ๐๐๐๐ซ ๐จ๐ฏ๐๐ซ๐๐ฅ๐จ๐ฐ - ๐ญ๐๐ฌ๐ณ๐ค.๐ข๐จ ๐ฅ๐๐๐ฌ โข CVE-2025-8065 is a stack buffer overflow affec
@PurpleOps_io
29 Apr 2026
107 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
#reversing #IoT_Security TP-Link Tapo C200: Hardcoded Keys, Buffer Overflows and Privacy in the Era of AI Assisted Reverse Engineering https://t.co/fZOpdbxgyp // CVE-2025-8065, CVE-2025-14299, CVE-2025-14300 See also: ]-> Awesome IoT and Hardware Security -
@ksg93rd
21 Dec 2025
206 Impressions
0 Retweets
2 Likes
2 Bookmarks
0 Replies
0 Quotes
CVE-2025-8065 A buffer overflow vulnerability exists in the ONVIF XML parser of Tapo C200 V3. An unauthenticated attacker on the same local network segment can send specially craftedโฆ https://t.co/4oqX4oup48
@CVEnew
20 Dec 2025
30 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-8065 Buffer Overflow in Tapo C200 V3 ONVIF XML Parser Enables Network DoS https://t.co/0yNeHiZNHD
@VulmonFeeds
20 Dec 2025
74 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:tp-link:tapo_c200_firmware:1.3.3:build_230228:*:*:*:*:*:*",
"matchCriteriaId": "CABD8DE6-9904-499D-919F-9DBD42BE6762",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:tp-link:tapo_c200_firmware:1.3.4:build_230424:*:*:*:*:*:*",
"matchCriteriaId": "254031B5-7CC7-4B9D-970B-FAA6EBC3EAFD",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:tp-link:tapo_c200_firmware:1.3.5:build_230717:*:*:*:*:*:*",
"matchCriteriaId": "9D61B481-8262-44D4-9A1D-9967AB1805DC",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:tp-link:tapo_c200_firmware:1.3.7:build_230920:*:*:*:*:*:*",
"matchCriteriaId": "50D2F368-F8C8-41E1-9360-8CDF9F89E566",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:tp-link:tapo_c200_firmware:1.3.9:build_231019:*:*:*:*:*:*",
"matchCriteriaId": "EF80958C-4274-4DEA-9730-176E3E6F21F2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:tp-link:tapo_c200_firmware:1.3.11:build_231115:*:*:*:*:*:*",
"matchCriteriaId": "7AA1B7FA-D418-46B2-A530-BF67E550E38F",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:tp-link:tapo_c200_firmware:1.3.13:build_240327:*:*:*:*:*:*",
"matchCriteriaId": "DC4382B5-C7EC-4B98-AF28-8D08D0771133",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:tp-link:tapo_c200_firmware:1.3.14:build_240513:*:*:*:*:*:*",
"matchCriteriaId": "1FCE1F5E-E84B-4CF4-B8A4-7A3448A0D127",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:tp-link:tapo_c200_firmware:1.3.15:build_240715:*:*:*:*:*:*",
"matchCriteriaId": "C05AC5C2-5BB7-499A-AE2B-414103317D47",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:tp-link:tapo_c200_firmware:1.4.1:build_241212:*:*:*:*:*:*",
"matchCriteriaId": "C1ED28D6-9441-440A-81D8-EB539D50BB56",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:tp-link:tapo_c200_firmware:1.4.2:build_250313:*:*:*:*:*:*",
"matchCriteriaId": "51E28752-8B46-48CD-86B5-437449AED7C0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:tp-link:tapo_c200_firmware:1.4.4:build_250922:*:*:*:*:*:*",
"matchCriteriaId": "ECBC265E-2AA6-471E-A7BE-8F35DDA28645",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
},
{
"cpeMatch": [
{
"criteria": "cpe:2.3:h:tp-link:tapo_c200:3:*:*:*:*:*:*:*",
"matchCriteriaId": "101FA54E-1A3D-4A38-BBD0-8DAFAC414EA3",
"vulnerable": false
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
}
]