Vulnerability Intelligence Report
Unauthenticated Access to connectAP API Endpoint on Tapo C100, C200 & C425
CVE-2025-14300
The HTTPS service on Tapo C200 v3, v5, C425 v1.2 and C100 v5 exposes a connectAP interface without proper authentication. An unauthenticated attacker on the same local network segment can exploit this to modify the device’s Wi-Fi configuration, resulting in loss of connectivity and denial-of-service (DoS).
No Active Exploit Signals
CVSS Base Score
8.7
HIGH
EPSS Probability:0.30%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-306 ↗CWE-306 Missing Authentication for Critical Function
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| TP-Link Systems Inc. | Tapo C200 | 0 < V3_1.4.5 Build 251104 (affected), 0 < V5_1.4.6 Build 260709 Rel.27675n (affected) |
| TP Link Systems Inc. | Tapo C100 v5 | 0 < V5_1.4.4 Build 260303 (affected) |
| TP Link Systems Inc. | Tapo C425 v1.2 | 0 < V1.20_1.2.27 Build 260518 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
0.302%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | TP-Link Systems Inc. · Vendor · USA |
| Reserved | 2025-12-08T22:05:13 |
| Published | 2025-12-20T00:43:39 |
| Last Updated | 2026-08-14T17:48:16 |
Community Chatter & Buzz