← Back to CVE List
Vulnerability Intelligence Report
Unauthenticated Access to connectAP API Endpoint on Tapo C100, C200 & C425

CVE-2025-14300

The HTTPS service on Tapo C200 v3, v5, C425 v1.2 and C100 v5  exposes a connectAP interface without proper authentication. An unauthenticated attacker on the same local network segment can exploit this to modify the device’s Wi-Fi configuration, resulting in loss of connectivity and denial-of-service (DoS).

No Active Exploit Signals
CVSS Base Score
8.7
HIGH
EPSS Probability:0.30%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-306 ↗CWE-306 Missing Authentication for Critical Function

Affected Products & Versions

Vendor Product Affected Versions
TP-Link Systems Inc. Tapo C200 0 < V3_1.4.5 Build 251104 (affected), 0 < V5_1.4.6 Build 260709 Rel.27675n (affected)
TP Link Systems Inc. Tapo C100 v5 0 < V5_1.4.4 Build 260303 (affected)
TP Link Systems Inc. Tapo C425 v1.2 0 < V1.20_1.2.27 Build 260518 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
0.302%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityTP-Link Systems Inc. · Vendor · USA
Reserved2025-12-08T22:05:13
Published2025-12-20T00:43:39
Last Updated2026-08-14T17:48:16

LINK COPIED TO CLIPBOARD