CVE-2025-14300: Unauthenticated Access to connectAP API Endpoint on Tapo C100, C200 & C425
The HTTPS service on Tapo C200 v3, v5, C425 v1.2 and C100 v5 exposes a connectAP interface without proper authentication. An unauthenticated attacker on the same local network segment can exploit this to modify the device’s Wi-Fi configuration, resulting in loss of connectivity and denial-of-service (DoS).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
For Tapo C200 v3 and v5, ensure the HTTPS connectAP interface is not exposed without proper authentication; restrict access so unauthenticated requests cannot modify Wi‑Fi configuration.
Tapo C200 (HTTPS) connectAP interface authentication = proper authentication required - Configuration
For Tapo C425 v1.2, ensure the HTTPS connectAP interface is not exposed without proper authentication; restrict access so unauthenticated requests cannot modify Wi‑Fi configuration.
Tapo C425 (HTTPS) connectAP interface authentication = proper authentication required - Configuration
For Tapo C100 v5, ensure the HTTPS connectAP interface is not exposed without proper authentication; restrict access so unauthenticated requests cannot modify Wi‑Fi configuration.
Tapo C100 (HTTPS) connectAP interface authentication = proper authentication required - Compensating control
Apply network-level restriction on the local network segment so only trusted clients can reach the device’s HTTPS service (where the connectAP endpoint is exposed), reducing the chance an unauthenticated local attacker can access it.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-14300?
CVE-2025-14300 is classified as a high severity vulnerability due to its potential to allow unauthenticated attackers to modify device configurations.
How do I fix CVE-2025-14300?
To fix CVE-2025-14300, ensure that your Tapo C200 firmware is updated to the latest version provided by TP-Link.
Who is affected by CVE-2025-14300?
CVE-2025-14300 affects users of the TP-Link Tapo C200 V3 camera with exposed connectAP service.
What type of attack can exploit CVE-2025-14300?
An attacker can exploit CVE-2025-14300 to perform a denial-of-service (DoS) attack by modifying the device's Wi-Fi configuration.
Is authentication required to exploit CVE-2025-14300?
No, CVE-2025-14300 can be exploited without authentication, making it particularly dangerous for local network segments.