CVE-2025-8065
MEDIUMDescription
A stack-based buffer overflow vulnerability was identified in the ONVIF SOAP XML Parser in Tapo C200 v3 and C520WS v2.6. When processing XML tags with namespace prefixes, the parser fails to validate the prefix length before copying it to a fixed-size stack buffer. It allowed a crafted SOAP request with an oversized namespace prefix to cause memory corruption in stack. An unauthenticated attacker on the same local network may exploit this flaw to enable remote code execution with elevated privileges, leading to full compromise of the device.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| tp-link | tapo_c200_firmware |
| tp-link | tapo_c200_firmware |
| tp-link | tapo_c200_firmware |
| tp-link | tapo_c200_firmware |
| tp-link | tapo_c200_firmware |
| tp-link | tapo_c200_firmware |
| tp-link | tapo_c200_firmware |
| tp-link | tapo_c200_firmware |
| tp-link | tapo_c200_firmware |
| tp-link | tapo_c200_firmware |
| tp-link | tapo_c200_firmware |
| tp-link | tapo_c200_firmware |
| tp-link | tapo_c200 |
References
Advisories & Patches
Other References
Frequently Asked Questions
What is CVE-2025-8065? +
How severe is CVE-2025-8065? +
What products are affected by CVE-2025-8065? +
How do I check if I'm vulnerable to CVE-2025-8065? +
Related Vulnerabilities
editorconfig-core-c is an EditorConfig core library for use by plugins supporting EditorConfig parsing. Versions up to and including 0.12.10 have …
Under certain circumstances the iSTAR Configuration Utility (ICU) tool could have a buffer overflow issue
A stack buffer overflow has been identified in the AsIO3.sys driver. This vulnerability can be triggered by input manipulation, may …
CWE-121: Stack-based Buffer Overflow vulnerability exists that could cause local attackers being able to exploit these issues to potentially execute …
Stack-based buffer overflow vulnerability in the 'conn-indicator' binary running as root on the TP-Link Archer AX50 router, in firmware versions …
PCSX2 is a free and open-source PlayStation 2 (PS2) emulator. A stack-based buffer overflow exists in the Kprintf_HLE function of …