CVE detail
CVE-2025-14300 — CVE-2025-14300
Published 2025-12-20 · Modified 2026-06-17 · Vendor tp-link · Product tapo_c200_firmware · Source nvd
HIGH
severity
CVSS-derived band
0.0030
EPSS probability
exploitation probability, 30d
22.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
The HTTPS service on Tapo C200 V3 exposes a connectAP interface without proper authentication. An unauthenticated attacker on the same local network segment can exploit this to modify the device’s Wi-Fi configuration, resulting in loss of connectivity and denial-of-service (DoS).
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References