Fiche vulnérabilité
CVE-2025-14300 : faille élevée tp-link tapo c200 firmware (CVSS 8.1)
Description
The HTTPS service on Tapo C200 v3, v5, C425 v1.2 and C100 v5 exposes a connectAP interface without proper authentication. An unauthenticated attacker on the same local network segment can exploit this to modify the device’s Wi-Fi configuration, resulting in loss of connectivity and denial-of-service (DoS).
En bref
- Sévérité
- Élevée (CVSS 8.1)
- Vecteur CVSS
- CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 20 déc. 2025
- Dernière mise à jour
- 14 août 2026
Produits concernés
- tp-link tapo c200 firmware
Références
- Fiche CVE-2025-14300 sur le NVD (NIST)
- tp-link.com/en/support/download/tapo-c100/v5/
- tp-link.com/en/support/download/tapo-c200/v3/
- tp-link.com/en/support/download/tapo-c200/v5/
- tp-link.com/en/support/download/tapo-c425/v1.20/
- tp-link.com/us/support/download/tapo-c100/v5/
- tp-link.com/us/support/download/tapo-c200/v3/
- tp-link.com/us/support/download/tapo-c200/v5/
- tp-link.com/us/support/download/tapo-c425/v1.20/
- tp-link.com/us/support/faq/4849/