Improper Content-Length Validation in HTTPS Requests on Tapo C200
Vulnerability Description
The HTTPS server on Tapo C200 V3 does not properly validate the Content-Length header, which can lead to an integer overflow. An unauthenticated attacker on the same local network segment can send crafted HTTPS requests to trigger excessive memory allocation, causing the device to crash and resulting in denial-of-service (DoS).
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-14299
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Simone Margaritelli (evilsocket)
References
More from TP-Link Systems Inc.
View All →Affected Vendor
TP-Link Systems Inc.
View all reports →