CVE-2025-8065
A stack-based buffer overflow vulnerability was identified in the ONVIF SOAP XML Parser in Tapo C200 v3 and C520WS v2.6. When processing XML tags with namespace prefixes, the parser fails to validate the prefix length before copying it to a fixed-size stack buffer. It allowed a crafted SOAP request with an oversized namespace prefix to cause memory corruption in stack.
An unauthenticated attacker on the same local network may exploit this flaw to enable remote code execution with elevated privileges, leading to full compromise of the device.
CVSS
- Versión: 4.0
- Vector: CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Puntuación base: 8.7
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.53%
- Percentil entre todas las CVEs puntuadas: 43
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1210Exploitation of Remote Serviceslateral movement85 % - Impacto principal
T1059Command and Scripting Interpreterexecution90 % - Impacto secundario
T1068Exploitation for Privilege Escalationprivilege escalation80 %
Buffer overflow en SOAP XML Parser de red adyacente (AV:A) sin autenticación ni interacción. Permite ejecución de código remoto con privilegios elevados en dispositivo IoT Tapo.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
CWE
- CWE-121
- CWE-120
Referencias
- https://www.tp-link.com/en/support/download/tapo-c200/v3/#Firmware-Release-Notes
- https://www.tp-link.com/en/support/download/tapo-c520ws/#Firmware-Release-Notes
- https://www.tp-link.com/us/support/download/tapo-c200/v3/#Firmware-Release-Notes
- https://www.tp-link.com/us/support/download/tapo-c520ws/#Firmware-Release-Notes
- https://www.tp-link.com/us/support/faq/4849/
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-8065",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-8065",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2025-12-22T16:07:36.027962Z"
}
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 6.5,
"attackVector": "ADJACENT_NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 2.8
}
],
"cvssMetricV40": [
{
"type": "Secondary",
"source": "f23511db-6c3e-4e32-a477-6aa17d310630",
"cvssData": {
"Safety": "NOT_DEFINED",
"version": "4.0",
"Recovery": "NOT_DEFINED",
"baseScore": 8.7,
"Automatable": "NOT_DEFINED",
"attackVector": "ADJACENT",
"baseSeverity": "HIGH",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"exploitMaturity": "NOT_DEFINED",
"providerUrgency": "NOT_DEFINED",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"privilegesRequired": "NONE",
"subIntegrityImpact": "NONE",
"vulnIntegrityImpact": "HIGH",
"integrityRequirement": "NOT_DEFINED",
"modifiedAttackVector": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"vulnAvailabilityImpact": "HIGH",
"availabilityRequirement": "NOT_DEFINED",
"modifiedUserInteraction": "NOT_DEFINED",
"modifiedAttackComplexity": "NOT_DEFINED",
"subConfidentialityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"confidentialityRequirement": "NOT_DEFINED",
"modifiedAttackRequirements": "NOT_DEFINED",
"modifiedPrivilegesRequired": "NOT_DEFINED",
"modifiedSubIntegrityImpact": "NOT_DEFINED",
"modifiedVulnIntegrityImpact": "NOT_DEFINED",
"vulnerabilityResponseEffort": "NOT_DEFINED",
"modifiedSubAvailabilityImpact": "NOT_DEFINED",
"modifiedVulnAvailabilityImpact": "NOT_DEFINED",
"modifiedSubConfidentialityImpact": "NOT_DEFINED",
"modifiedVulnConfidentialityImpact": "NOT_DEFINED"
}
}
]
},
"affected": [
{
"source": "f23511db-6c3e-4e32-a477-6aa17d310630",
"affectedData": [
{
"vendor": "TP-Link Systems Inc.",
"modules": [
"ONVIF Server"
],
"product": "Tapo C200 V3",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "V3_1.4.5 Build 251104",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
},
{
"vendor": "TP-Link Systems Inc.",
"product": "Tapo C520WS v2.6",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "1.2.4 Build 260326 Rel.24666n",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2025-12-20T01:16:05.410",
"references": [
{
"url": "https://www.tp-link.com/en/support/download/tapo-c200/v3/#Firmware-Release-Notes",
"source": "f23511db-6c3e-4e32-a477-6aa17d310630"
},
{
"url": "https://www.tp-link.com/en/support/download/tapo-c520ws/#Firmware-Release-Notes",
"source": "f23511db-6c3e-4e32-a477-6aa17d310630"
},
{
"url": "https://www.tp-link.com/us/support/download/tapo-c200/v3/#Firmware-Release-Notes",
"tags": [
"Release Notes"
],
"source": "f23511db-6c3e-4e32-a477-6aa17d310630"
},
{
"url": "https://www.tp-link.com/us/support/download/tapo-c520ws/#Firmware-Release-Notes",
"source": "f23511db-6c3e-4e32-a477-6aa17d310630"
},
{
"url": "https://www.tp-link.com/us/support/faq/4849/",
"tags": [
"Vendor Advisory"
],
"source": "f23511db-6c3e-4e32-a477-6aa17d310630"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "f23511db-6c3e-4e32-a477-6aa17d310630",
"description": [
{
"lang": "en",
"value": "CWE-121"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-120"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A stack-based buffer overflow vulnerability was identified in the ONVIF SOAP XML Parser in Tapo C200 v3 and C520WS v2.6. When processing XML tags with namespace prefixes, the parser fails to validate the prefix length before copying it to a fixed-size stack buffer. It allowed a crafted SOAP request with an oversized namespace prefix to cause memory corruption in stack. \n\nAn unauthenticated attacker on the same local network may exploit this flaw to enable remote code execution with elevated privileges, leading to full compromise of the device."
},
{
"lang": "es",
"value": "Una vulnerabilidad de desbordamiento de búfer existe en el analizador XML ONVIF de Tapo C200 V3. Un atacante no autenticado en el mismo segmento de red local puede enviar solicitudes XML SOAP especialmente diseñadas, causando un desbordamiento de memoria y un fallo del dispositivo, lo que resulta en una denegación de servicio (DoS)."
}
],
"lastModified": "2026-09-25T23:10:00.463",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:tp-link:tapo_c200_firmware:1.3.3:build_230228:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CABD8DE6-9904-499D-919F-9DBD42BE6762"
},
{
"criteria": "cpe:2.3:o:tp-link:tapo_c200_firmware:1.3.4:build_230424:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "254031B5-7CC7-4B9D-970B-FAA6EBC3EAFD"
},
{
"criteria": "cpe:2.3:o:tp-link:tapo_c200_firmware:1.3.5:build_230717:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9D61B481-8262-44D4-9A1D-9967AB1805DC"
},
{
"criteria": "cpe:2.3:o:tp-link:tapo_c200_firmware:1.3.7:build_230920:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "50D2F368-F8C8-41E1-9360-8CDF9F89E566"
},
{
"criteria": "cpe:2.3:o:tp-link:tapo_c200_firmware:1.3.9:build_231019:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EF80958C-4274-4DEA-9730-176E3E6F21F2"
},
{
"criteria": "cpe:2.3:o:tp-link:tapo_c200_firmware:1.3.11:build_231115:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7AA1B7FA-D418-46B2-A530-BF67E550E38F"
},
{
"criteria": "cpe:2.3:o:tp-link:tapo_c200_firmware:1.3.13:build_240327:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DC4382B5-C7EC-4B98-AF28-8D08D0771133"
},
{
"criteria": "cpe:2.3:o:tp-link:tapo_c200_firmware:1.3.14:build_240513:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1FCE1F5E-E84B-4CF4-B8A4-7A3448A0D127"
},
{
"criteria": "cpe:2.3:o:tp-link:tapo_c200_firmware:1.3.15:build_240715:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C05AC5C2-5BB7-499A-AE2B-414103317D47"
},
{
"criteria": "cpe:2.3:o:tp-link:tapo_c200_firmware:1.4.1:build_241212:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C1ED28D6-9441-440A-81D8-EB539D50BB56"
},
{
"criteria": "cpe:2.3:o:tp-link:tapo_c200_firmware:1.4.2:build_250313:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "51E28752-8B46-48CD-86B5-437449AED7C0"
},
{
"criteria": "cpe:2.3:o:tp-link:tapo_c200_firmware:1.4.4:build_250922:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "ECBC265E-2AA6-471E-A7BE-8F35DDA28645"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:tp-link:tapo_c200:3:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "101FA54E-1A3D-4A38-BBD0-8DAFAC414EA3"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "f23511db-6c3e-4e32-a477-6aa17d310630"
}