CVE-2025-8065 Details
Description
A stack-based buffer overflow vulnerability was identified in the ONVIF SOAP XML Parser in Tapo C200 v3 and C520WS v2.6. When processing XML tags with namespace prefixes, the parser fails to validate the prefix length before copying it to a fixed-size stack buffer. It allowed a crafted SOAP request with an oversized namespace prefix to cause memory corruption in stack. An unauthenticated attacker on the same local network may exploit this flaw to enable remote code execution with elevated privileges, leading to full compromise of the device.
A buffer overflow vulnerability has been identified in the ONVIF XML parser of the TP-Link Tapo C200 V3 camera. This vulnerability allows an unauthenticated attacker on the same local network segment to send specially crafted SOAP XML requests. The exploitation of this vulnerability causes a memory overflow, leading to a device crash and a denial-of-service condition.
Users are advised to check for updates on the Tapo Mobile Application to address this vulnerability. The latest firmware version can be downloaded from the TP-Link Tapo C200 V3 support page.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Dec 22, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-120 | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') | [email protected] |
| CWE-121 | Stack-based Buffer Overflow | TPLink |
Affected Products
| Product | Versions |
|---|---|
| tp-link tapo c200 firmware | 1.3.3 build_230228 1.3.4 build_230424 1.3.5 build_230717 1.3.7 build_230920 1.3.9 build_231019 1.3.11 build_231115 1.3.13 build_240327 1.3.14 build_240513 1.3.15 build_240715 1.4.1 build_241212 1.4.2 build_250313 1.4.4 build_250922 |
CPE
Remediation
| |
| tp-link tapo c200 | 3 |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 25, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | TPLink |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 3, 2026 | CVE Modified | TPLink |
| Apr 2, 2026 | CVE Modified | TPLink |
| Jan 8, 2026 | Initial Analysis | [email protected] |
| Dec 20, 2025 | New CVE Received | TPLink |