---
id: CVE-2025-14300
title: "The HTTPS service on Tapo C200 v3, v5, C425 v1.2 and C100 v5\_ exposes a connectAP interface without proper authentication"
summary: "The HTTPS service on Tapo C200 v3, v5, C425 v1.2 and C100 v5\_ exposes a connectAP interface without proper authentication. An unauthenticated attacker on the same local network segment can exploit this to modify the device’s Wi-Fi config…"
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H'
cwe:
  - CWE-306
vendor: tp-link
product: tapo_c200_firmware
affected:
  - tapo_c200_firmware = 1.3.3
  - tapo_c200_firmware = 1.3.4
  - tapo_c200_firmware = 1.3.5
  - tapo_c200_firmware = 1.3.7
  - tapo_c200_firmware = 1.3.9
  - tapo_c200_firmware = 1.3.11
  - tapo_c200_firmware = 1.3.13
  - tapo_c200_firmware = 1.3.14
  - tapo_c200_firmware = 1.3.15
  - tapo_c200_firmware = 1.4.1
  - tapo_c200_firmware = 1.4.2
  - tapo_c200_firmware = 1.4.4
published: '2025-12-20'
updated: '2026-08-14'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-14300'
references:
  - url: >-
      https://www.tp-link.com/en/support/download/tapo-c100/v5/#Firmware-Release-Notes
    label: f23511db-6c3e-4e32-a477-6aa17d310630
  - url: >-
      https://www.tp-link.com/en/support/download/tapo-c200/v3/#Firmware-Release-Notes
    label: f23511db-6c3e-4e32-a477-6aa17d310630
  - url: >-
      https://www.tp-link.com/en/support/download/tapo-c200/v5/#Firmware-Release-Notes
    label: f23511db-6c3e-4e32-a477-6aa17d310630
  - url: >-
      https://www.tp-link.com/en/support/download/tapo-c425/v1.20/#Firmware-Release-Notes
    label: f23511db-6c3e-4e32-a477-6aa17d310630
  - url: >-
      https://www.tp-link.com/us/support/download/tapo-c100/v5/#Firmware-Release-Notes
    label: f23511db-6c3e-4e32-a477-6aa17d310630
  - url: >-
      https://www.tp-link.com/us/support/download/tapo-c200/v3/#Firmware-Release-Notes
    label: f23511db-6c3e-4e32-a477-6aa17d310630
  - url: >-
      https://www.tp-link.com/us/support/download/tapo-c200/v5/#Firmware-Release-Notes
    label: f23511db-6c3e-4e32-a477-6aa17d310630
  - url: >-
      https://www.tp-link.com/us/support/download/tapo-c425/v1.20/#Firmware-Release-Notes
    label: f23511db-6c3e-4e32-a477-6aa17d310630
  - url: 'https://www.tp-link.com/us/support/faq/4849/'
    label: f23511db-6c3e-4e32-a477-6aa17d310630
tags:
  - nvd
epss: 0.00368
epssPercentile: 0.28013
ingestedAt: '2026-08-14T18:19:41.287Z'
---

## Overview

The HTTPS service on Tapo C200 v3, v5, C425 v1.2 and C100 v5  exposes a connectAP interface without proper authentication. An unauthenticated attacker on the same local network segment can exploit this to modify the device’s Wi-Fi configuration, resulting in loss of connectivity and denial-of-service (DoS).

## Affected

- `tapo_c200_firmware = 1.3.3`
- `tapo_c200_firmware = 1.3.4`
- `tapo_c200_firmware = 1.3.5`
- `tapo_c200_firmware = 1.3.7`
- `tapo_c200_firmware = 1.3.9`
- `tapo_c200_firmware = 1.3.11`
- `tapo_c200_firmware = 1.3.13`
- `tapo_c200_firmware = 1.3.14`
- `tapo_c200_firmware = 1.3.15`
- `tapo_c200_firmware = 1.4.1`
- `tapo_c200_firmware = 1.4.2`
- `tapo_c200_firmware = 1.4.4`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
