CVE Explorer
CVE-2025-8065
A stack-based buffer overflow vulnerability was identified in the ONVIF SOAP XML Parser in Tapo C200 v3 and C520WS v2.6. When processing XML tags with namespace prefixes, the parser fails to validate the prefix length before copying it to a fixed-size stack buffer. It allowed a crafted SOAP request with an oversized namespace prefix to cause memory corruption in stack.
An unauthenticated attacker on the same local network may exploit this flaw to enable remote code execution with elevated pri
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
affected · 2 assertions
{"defaultStatus":"unaffected","product":"Tapo C520WS v2.6","vendor":"TP-Link Systems Inc.","versions":[{"lessThan":"1.2.4 Build 260326 Rel.24666n","status":"affected","version":"0","versionType":"custom"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:b2c860381655756048d54bad1daba543167827fed6aa7d0f2f46b9f7d0680c46 · sha256:169cc5d5cc9a487b… · /containers/cna/affected/1
{"defaultStatus":"unaffected","modules":["ONVIF Server"],"product":"Tapo C200 V3","vendor":"TP-Link Systems Inc.","versions":[{"lessThan":"V3_1.4.5 Build 251104","status":"affected","version":"0","versionType":"custom"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:b2c860381655756048d54bad1daba543167827fed6aa7d0f2f46b9f7d0680c46 · sha256:169cc5d5cc9a487b… · /containers/cna/affected/0
Affected products and versions
2 source assertions{"defaultStatus":"unaffected","product":"Tapo C520WS v2.6","vendor":"TP-Link Systems Inc.","versions":[{"lessThan":"1.2.4 Build 260326 Rel.24666n","status":"affected","version":"0","versionType":"custom"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:b2c860381655756048d54bad1daba543167827fed6aa7d0f2f46b9f7d0680c46 · sha256:169cc5d5cc9a487b… · /containers/cna/affected/1
{"defaultStatus":"unaffected","modules":["ONVIF Server"],"product":"Tapo C200 V3","vendor":"TP-Link Systems Inc.","versions":[{"lessThan":"V3_1.4.5 Build 251104","status":"affected","version":"0","versionType":"custom"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:b2c860381655756048d54bad1daba543167827fed6aa7d0f2f46b9f7d0680c46 · sha256:169cc5d5cc9a487b… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"ADJACENT","baseScore":8.7,"baseSeverity":"HIGH","exploitMaturity":"NOT_DEFINED","privilegesRequired":"NONE","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpact":…
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:b2c860381655756048d54bad1daba543167827fed6aa7d0f2f46b9f7d0680c46 · sha256:169cc5d5cc9a487b… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-121","description":"CWE-121 Stack-based buffer overflow","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:b2c860381655756048d54bad1daba543167827fed6aa7d0f2f46b9f7d0680c46 · sha256:169cc5d5cc9a487b… · /containers/cna/problemTypes/0/descriptions/0
Source references
5 source assertions{"tags":["patch"],"url":"https://www.tp-link.com/en/support/download/tapo-c200/v3/#Firmware-Release-Notes"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:b2c860381655756048d54bad1daba543167827fed6aa7d0f2f46b9f7d0680c46 · sha256:169cc5d5cc9a487b… · /containers/cna/references/4
{"tags":["patch"],"url":"https://www.tp-link.com/en/support/download/tapo-c520ws/#Firmware-Release-Notes"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:b2c860381655756048d54bad1daba543167827fed6aa7d0f2f46b9f7d0680c46 · sha256:169cc5d5cc9a487b… · /containers/cna/references/3
{"tags":["patch"],"url":"https://www.tp-link.com/us/support/download/tapo-c200/v3/#Firmware-Release-Notes"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:b2c860381655756048d54bad1daba543167827fed6aa7d0f2f46b9f7d0680c46 · sha256:169cc5d5cc9a487b… · /containers/cna/references/0
{"tags":["patch"],"url":"https://www.tp-link.com/us/support/download/tapo-c520ws/#Firmware-Release-Notes"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:b2c860381655756048d54bad1daba543167827fed6aa7d0f2f46b9f7d0680c46 · sha256:169cc5d5cc9a487b… · /containers/cna/references/2
{"tags":["vendor-advisory"],"url":"https://www.tp-link.com/us/support/faq/4849/"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:b2c860381655756048d54bad1daba543167827fed6aa7d0f2f46b9f7d0680c46 · sha256:169cc5d5cc9a487b… · /containers/cna/references/1
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.