« Volver al listado

CVE-2025-8065

Estado: ModificadaAlta (8.7)—

A stack-based buffer overflow vulnerability was identified in the ONVIF SOAP XML Parser in Tapo C200 v3 and C520WS v2.6. When processing XML tags with namespace prefixes, the parser fails to validate the prefix length before copying it to a fixed-size stack buffer. It allowed a crafted SOAP request with an oversized namespace prefix to cause memory corruption in stack.

An unauthenticated attacker on the same local network may exploit this flaw to enable remote code execution with elevated privileges, leading to full compromise of the device.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Buffer overflow en SOAP XML Parser de red adyacente (AV:A) sin autenticación ni interacción. Permite ejecución de código remoto con privilegios elevados en dispositivo IoT Tapo.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-8065",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-8065",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-12-22T16:07:36.027962Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "ADJACENT_NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.8
      }
    ],
    "cvssMetricV40": [
      {
        "type": "Secondary",
        "source": "f23511db-6c3e-4e32-a477-6aa17d310630",
        "cvssData": {
          "Safety": "NOT_DEFINED",
          "version": "4.0",
          "Recovery": "NOT_DEFINED",
          "baseScore": 8.7,
          "Automatable": "NOT_DEFINED",
          "attackVector": "ADJACENT",
          "baseSeverity": "HIGH",
          "valueDensity": "NOT_DEFINED",
          "vectorString": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
          "exploitMaturity": "NOT_DEFINED",
          "providerUrgency": "NOT_DEFINED",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "attackRequirements": "NONE",
          "privilegesRequired": "NONE",
          "subIntegrityImpact": "NONE",
          "vulnIntegrityImpact": "HIGH",
          "integrityRequirement": "NOT_DEFINED",
          "modifiedAttackVector": "NOT_DEFINED",
          "subAvailabilityImpact": "NONE",
          "vulnAvailabilityImpact": "HIGH",
          "availabilityRequirement": "NOT_DEFINED",
          "modifiedUserInteraction": "NOT_DEFINED",
          "modifiedAttackComplexity": "NOT_DEFINED",
          "subConfidentialityImpact": "NONE",
          "vulnConfidentialityImpact": "HIGH",
          "confidentialityRequirement": "NOT_DEFINED",
          "modifiedAttackRequirements": "NOT_DEFINED",
          "modifiedPrivilegesRequired": "NOT_DEFINED",
          "modifiedSubIntegrityImpact": "NOT_DEFINED",
          "modifiedVulnIntegrityImpact": "NOT_DEFINED",
          "vulnerabilityResponseEffort": "NOT_DEFINED",
          "modifiedSubAvailabilityImpact": "NOT_DEFINED",
          "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
          "modifiedSubConfidentialityImpact": "NOT_DEFINED",
          "modifiedVulnConfidentialityImpact": "NOT_DEFINED"
        }
      }
    ]
  },
  "affected": [
    {
      "source": "f23511db-6c3e-4e32-a477-6aa17d310630",
      "affectedData": [
        {
          "vendor": "TP-Link Systems Inc.",
          "modules": [
            "ONVIF Server"
          ],
          "product": "Tapo C200 V3",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "V3_1.4.5 Build 251104",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "TP-Link Systems Inc.",
          "product": "Tapo C520WS v2.6",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "1.2.4 Build 260326 Rel.24666n",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2025-12-20T01:16:05.410",
  "references": [
    {
      "url": "https://www.tp-link.com/en/support/download/tapo-c200/v3/#Firmware-Release-Notes",
      "source": "f23511db-6c3e-4e32-a477-6aa17d310630"
    },
    {
      "url": "https://www.tp-link.com/en/support/download/tapo-c520ws/#Firmware-Release-Notes",
      "source": "f23511db-6c3e-4e32-a477-6aa17d310630"
    },
    {
      "url": "https://www.tp-link.com/us/support/download/tapo-c200/v3/#Firmware-Release-Notes",
      "tags": [
        "Release Notes"
      ],
      "source": "f23511db-6c3e-4e32-a477-6aa17d310630"
    },
    {
      "url": "https://www.tp-link.com/us/support/download/tapo-c520ws/#Firmware-Release-Notes",
      "source": "f23511db-6c3e-4e32-a477-6aa17d310630"
    },
    {
      "url": "https://www.tp-link.com/us/support/faq/4849/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "f23511db-6c3e-4e32-a477-6aa17d310630"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "f23511db-6c3e-4e32-a477-6aa17d310630",
      "description": [
        {
          "lang": "en",
          "value": "CWE-121"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-120"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A stack-based buffer overflow vulnerability was identified in the ONVIF SOAP XML Parser in Tapo C200 v3 and C520WS v2.6. When processing XML tags with namespace prefixes, the parser fails to validate the prefix length before copying it to a fixed-size stack buffer.  It allowed a crafted SOAP request with an oversized namespace prefix to cause memory corruption in stack. \n\nAn unauthenticated attacker on the same local network may exploit this flaw to enable remote code execution with elevated privileges, leading to full compromise of the device."
    },
    {
      "lang": "es",
      "value": "Una vulnerabilidad de desbordamiento de búfer existe en el analizador XML ONVIF de Tapo C200 V3. Un atacante no autenticado en el mismo segmento de red local puede enviar solicitudes XML SOAP especialmente diseñadas, causando un desbordamiento de memoria y un fallo del dispositivo, lo que resulta en una denegación de servicio (DoS)."
    }
  ],
  "lastModified": "2026-09-25T23:10:00.463",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:tp-link:tapo_c200_firmware:1.3.3:build_230228:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CABD8DE6-9904-499D-919F-9DBD42BE6762"
            },
            {
              "criteria": "cpe:2.3:o:tp-link:tapo_c200_firmware:1.3.4:build_230424:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "254031B5-7CC7-4B9D-970B-FAA6EBC3EAFD"
            },
            {
              "criteria": "cpe:2.3:o:tp-link:tapo_c200_firmware:1.3.5:build_230717:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9D61B481-8262-44D4-9A1D-9967AB1805DC"
            },
            {
              "criteria": "cpe:2.3:o:tp-link:tapo_c200_firmware:1.3.7:build_230920:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "50D2F368-F8C8-41E1-9360-8CDF9F89E566"
            },
            {
              "criteria": "cpe:2.3:o:tp-link:tapo_c200_firmware:1.3.9:build_231019:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EF80958C-4274-4DEA-9730-176E3E6F21F2"
            },
            {
              "criteria": "cpe:2.3:o:tp-link:tapo_c200_firmware:1.3.11:build_231115:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7AA1B7FA-D418-46B2-A530-BF67E550E38F"
            },
            {
              "criteria": "cpe:2.3:o:tp-link:tapo_c200_firmware:1.3.13:build_240327:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DC4382B5-C7EC-4B98-AF28-8D08D0771133"
            },
            {
              "criteria": "cpe:2.3:o:tp-link:tapo_c200_firmware:1.3.14:build_240513:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1FCE1F5E-E84B-4CF4-B8A4-7A3448A0D127"
            },
            {
              "criteria": "cpe:2.3:o:tp-link:tapo_c200_firmware:1.3.15:build_240715:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C05AC5C2-5BB7-499A-AE2B-414103317D47"
            },
            {
              "criteria": "cpe:2.3:o:tp-link:tapo_c200_firmware:1.4.1:build_241212:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C1ED28D6-9441-440A-81D8-EB539D50BB56"
            },
            {
              "criteria": "cpe:2.3:o:tp-link:tapo_c200_firmware:1.4.2:build_250313:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "51E28752-8B46-48CD-86B5-437449AED7C0"
            },
            {
              "criteria": "cpe:2.3:o:tp-link:tapo_c200_firmware:1.4.4:build_250922:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "ECBC265E-2AA6-471E-A7BE-8F35DDA28645"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:tp-link:tapo_c200:3:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "101FA54E-1A3D-4A38-BBD0-8DAFAC414EA3"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "f23511db-6c3e-4e32-a477-6aa17d310630"
}