---
id: CVE-2025-8065
title: >-
  A stack-based buffer overflow vulnerability was identified in the ONVIF SOAP
  XML Parser in Tapo C200 v3 and C520WS v2.6
summary: >-
  A stack-based buffer overflow vulnerability was identified in the ONVIF SOAP
  XML Parser in Tapo C200 v3 and C520WS v2.6. When processing XML tags with
  namespace prefixes, the parser fails to validate the prefix length before
  copying it t…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-121
  - CWE-120
vendor: tp-link
product: tapo_c200_firmware
affected:
  - tapo_c200_firmware = 1.3.3
  - tapo_c200_firmware = 1.3.4
  - tapo_c200_firmware = 1.3.5
  - tapo_c200_firmware = 1.3.7
  - tapo_c200_firmware = 1.3.9
  - tapo_c200_firmware = 1.3.11
  - tapo_c200_firmware = 1.3.13
  - tapo_c200_firmware = 1.3.14
  - tapo_c200_firmware = 1.3.15
  - tapo_c200_firmware = 1.4.1
  - tapo_c200_firmware = 1.4.2
  - tapo_c200_firmware = 1.4.4
published: '2025-12-20'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T23:10:00.463'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-8065'
references:
  - url: >-
      https://www.tp-link.com/en/support/download/tapo-c200/v3/#Firmware-Release-Notes
    label: f23511db-6c3e-4e32-a477-6aa17d310630
  - url: >-
      https://www.tp-link.com/en/support/download/tapo-c520ws/#Firmware-Release-Notes
    label: f23511db-6c3e-4e32-a477-6aa17d310630
  - url: >-
      https://www.tp-link.com/us/support/download/tapo-c200/v3/#Firmware-Release-Notes
    label: f23511db-6c3e-4e32-a477-6aa17d310630
  - url: >-
      https://www.tp-link.com/us/support/download/tapo-c520ws/#Firmware-Release-Notes
    label: f23511db-6c3e-4e32-a477-6aa17d310630
  - url: 'https://www.tp-link.com/us/support/faq/4849/'
    label: f23511db-6c3e-4e32-a477-6aa17d310630
tags:
  - nvd
epss: 0.00535
epssPercentile: 0.42725
ingestedAt: '2026-09-25T23:21:16.950Z'
---

## Overview

A stack-based buffer overflow vulnerability was identified in the ONVIF SOAP XML Parser in Tapo C200 v3 and C520WS v2.6. When processing XML tags with namespace prefixes, the parser fails to validate the prefix length before copying it to a fixed-size stack buffer.  It allowed a crafted SOAP request with an oversized namespace prefix to cause memory corruption in stack. 

An unauthenticated attacker on the same local network may exploit this flaw to enable remote code execution with elevated privileges, leading to full compromise of the device.

## Affected

- `tapo_c200_firmware = 1.3.3`
- `tapo_c200_firmware = 1.3.4`
- `tapo_c200_firmware = 1.3.5`
- `tapo_c200_firmware = 1.3.7`
- `tapo_c200_firmware = 1.3.9`
- `tapo_c200_firmware = 1.3.11`
- `tapo_c200_firmware = 1.3.13`
- `tapo_c200_firmware = 1.3.14`
- `tapo_c200_firmware = 1.3.15`
- `tapo_c200_firmware = 1.4.1`
- `tapo_c200_firmware = 1.4.2`
- `tapo_c200_firmware = 1.4.4`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
