Answer in brief
CVE-2025-14300 records a Unknown severity vulnerability in Unauthenticated Access to connectAP API Endpoint on Tapo C100, C200 & C425. The current sources do not mark it as known exploited. The current feed maps TP Link Systems Inc./Tapo C100 v5 (generic), TP-Link Systems Inc./Tapo C200 (generic), TP Link Systems Inc./Tapo C425 v1.2 (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
Answer in brief
CVE-2025-14300 records a Unknown severity vulnerability in Unauthenticated Access to connectAP API Endpoint on Tapo C100, C200 & C425. The current sources do not mark it as known exploited. The current feed maps TP Link Systems Inc./Tapo C100 v5 (generic), TP-Link Systems Inc./Tapo C200 (generic), TP Link Systems Inc./Tapo C425 v1.2 (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps TP Link Systems Inc./Tapo C100 v5 (generic), TP-Link Systems Inc./Tapo C200 (generic), TP Link Systems Inc./Tapo C425 v1.2 (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| TP Link Systems Inc./Tapo C100 v5generic | >=0 <V5_1.4.4 Build 260303 | V5_1.4.4 Build 260303 |
| TP-Link Systems Inc./Tapo C200generic | >=0 <V3_1.4.5 Build 251104 || >=0 <V5_1.4.6 Build 260709 Rel.27675n | V3_1.4.5 Build 251104, V5_1.4.6 Build 260709 Rel.27675n |
| TP Link Systems Inc./Tapo C425 v1.2generic | >=0 <V1.20_1.2.27 Build 260518 | V1.20_1.2.27 Build 260518 |
Published upstream
Dec 20, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 14, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 14, 2026
The HTTPS service on Tapo C200 v3, v5, C425 v1.2 and C100 v5 exposes a connectAP interface without proper authentication. An unauthenticated attacker on the same local network segment can exploit this to modify the device’s Wi-Fi configuration, resulting in loss of connectivity and denial-of-service (DoS).
Quoted source text, attributed separately from HOL analysis.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps TP Link Systems Inc./Tapo C100 v5 (generic), TP-Link Systems Inc./Tapo C200 (generic), TP Link Systems Inc./Tapo C425 v1.2 (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| TP Link Systems Inc./Tapo C100 v5generic | >=0 <V5_1.4.4 Build 260303 | V5_1.4.4 Build 260303 |
| TP-Link Systems Inc./Tapo C200generic | >=0 <V3_1.4.5 Build 251104 || >=0 <V5_1.4.6 Build 260709 Rel.27675n | V3_1.4.5 Build 251104, V5_1.4.6 Build 260709 Rel.27675n |
| TP Link Systems Inc./Tapo C425 v1.2generic | >=0 <V1.20_1.2.27 Build 260518 | V1.20_1.2.27 Build 260518 |
Published upstream
Dec 20, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 14, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 14, 2026
The HTTPS service on Tapo C200 v3, v5, C425 v1.2 and C100 v5 exposes a connectAP interface without proper authentication. An unauthenticated attacker on the same local network segment can exploit this to modify the device’s Wi-Fi configuration, resulting in loss of connectivity and denial-of-service (DoS).
Quoted source text, attributed separately from HOL analysis.