CVE-2025-14300

The HTTPS service on Tapo C200 V3 exposes a connectAP interface without proper authentication. An unauthenticated attacker on the same local network segment can exploit this to modify the device’s Wi-Fi configuration, resulting in loss of connectivity and denial-of-service (DoS).

high 8.1 CVSS 3.1
Published: Dec 20, 2025
Modified: Apr 3, 2026
Vendor: Tp-Link
Product: Tapo C200 Firmware
Versions: 1.3.3,1.3.4,1.3.5,1.3.7,1.3.9,1.3.11,1.3.13,1.3.14,1.3.15,1.4.1

Description

The HTTPS service on Tapo C200 V3 exposes a connectAP interface without proper authentication. An unauthenticated attacker on the same local network segment can exploit this to modify the device’s Wi-Fi configuration, resulting in loss of connectivity and denial-of-service (DoS).

References

Related CVEs