CVE-2025-14299
MEDIUMDescription
The HTTPS server on Tapo C200 V3 does not properly validate the Content-Length header, which can lead to an integer overflow. An unauthenticated attacker on the same local network segment can send crafted HTTPS requests to trigger excessive memory allocation, causing the device to crash and resulting in denial-of-service (DoS).
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| tp-link | tapo_c200_firmware |
| tp-link | tapo_c200_firmware |
| tp-link | tapo_c200_firmware |
| tp-link | tapo_c200_firmware |
| tp-link | tapo_c200_firmware |
| tp-link | tapo_c200_firmware |
| tp-link | tapo_c200_firmware |
| tp-link | tapo_c200_firmware |
| tp-link | tapo_c200_firmware |
| tp-link | tapo_c200_firmware |
| tp-link | tapo_c200_firmware |
| tp-link | tapo_c200_firmware |
| tp-link | tapo_c200 |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2025-14299? +
How severe is CVE-2025-14299? +
What products are affected by CVE-2025-14299? +
How do I check if I'm vulnerable to CVE-2025-14299? +
Related Vulnerabilities
mcp-framework is a framework for building Model Context Protocol (MCP) servers. In versions 0.2.21 and below, the readRequestBody() function in …
spdystream is a Go library for multiplexing streams over SPDY connections. In versions 0.5.0 and below, the SPDY/3 frame parser …
Allocation of Resources Without Limits or Throttling vulnerability in mtrudel bandit allows unauthenticated remote denial of service via memory exhaustion. …
Allocation of Resources Without Limits or Throttling vulnerability in mtrudel bandit allows unauthenticated remote denial of service via memory exhaustion …
Allocation of Resources Without Limits or Throttling vulnerability in elixir-plug plug_cowboy allows unauthenticated remote denial of service via atom table …
An Allocation of Resources Without Limits or Throttling vulnerability in the operating system network configuration used in B&R APROL <4.4-00P5 …