Executive brief
TP-Link Tapo security cameras (C200, C425, C100 models) expose an unauthenticated Wi-Fi configuration interface accessible over HTTPS to devices on the local network. An attacker on the same network can reconfigure the camera's Wi-Fi settings without needing any credentials, causing it to disconnect from the network and become unusable until manually reconfigured.
Technical details
The vulnerability is an authentication bypass in the connectAP interface exposed by the HTTPS service on affected Tapo camera models. The root cause is insufficient access control on a Wi-Fi configuration endpoint that should require authentication. An unauthenticated attacker on the same local network segment can send requests to modify the device's Wi-Fi configuration parameters, resulting in loss of network connectivity. Attack preconditions are minimal: attacker must be on the adjacent network segment (local LAN). The impact is denial of service, as the affected camera loses connectivity and cannot be accessed remotely until reconnected manually. A patch is expected to introduce proper authentication checks on the connectAP interface.
Affected products
- TP-Link Tapo C200 v3, v5
- TP-Link Tapo C425 v1.2
- TP-Link Tapo C100 v5
Timeline
- 2025-12-20: disclosed: CVE-2025-14300 published