CVE-2025-14299: Improper Content-Length Validation in HTTPS Requests on Tapo C200
The HTTPS server on Tapo C200 V3 does not properly validate the Content-Length header, which can lead to an integer overflow. An unauthenticated attacker on the same local network segment can send crafted HTTPS requests to trigger excessive memory allocation, causing the device to crash and resulting in denial-of-service (DoS).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-14299?
CVE-2025-14299 is classified as a high severity vulnerability due to its potential to allow unauthorized access and exploit memory allocation issues.
How do I fix CVE-2025-14299?
To mitigate CVE-2025-14299, users should update their TP-Link Tapo C200 to the latest firmware version that addresses this vulnerability.
What could happen if I don't address CVE-2025-14299?
Failing to address CVE-2025-14299 may lead to an attacker being able to cause denial of service or potentially execute arbitrary code on the device.
Who is affected by CVE-2025-14299?
CVE-2025-14299 affects TP-Link Tapo C200 cameras running version V3 firmware.
Is authentication required to exploit CVE-2025-14299?
No, CVE-2025-14299 can be exploited by unauthenticated attackers on the same local network segment.