CVE-2025-8065 Overview
CVE-2025-8065 is a stack-based buffer overflow [CWE-121] in the Open Network Video Interface Forum (ONVIF) Simple Object Access Protocol (SOAP) XML parser used by TP-Link Tapo C200 v3 and Tapo C520WS v2.6 network cameras. The parser copies XML namespace prefixes to a fixed-size stack buffer without validating their length. A crafted SOAP request with an oversized namespace prefix corrupts stack memory. An unauthenticated attacker on the same local network can trigger the flaw to achieve remote code execution with elevated privileges, leading to full device compromise.
Critical Impact
Unauthenticated adjacent-network attackers can gain elevated code execution on affected Tapo cameras, exposing live video feeds and pivoting opportunities into internal networks.
Affected Products
- TP-Link Tapo C200 v3 firmware versions from 1.3.3 build 230228 through 1.4.4 build 250922
- TP-Link Tapo C520WS v2.6
- ONVIF SOAP XML Parser component shipped in the above camera firmware
Discovery Timeline
- 2025-12-20 - CVE-2025-8065 published to the National Vulnerability Database (NVD)
- 2026-06-17 - Last updated in NVD database
Technical Details for CVE-2025-8065
Vulnerability Analysis
The Tapo C200 v3 and C520WS v2.6 cameras expose an ONVIF service that accepts SOAP-based XML requests over the local network. SOAP messages use XML namespaces, where element and attribute names are prefixed with a short identifier (for example, soap:Envelope or tds:GetDeviceInformation). The vulnerable parser reads the prefix portion of each qualified name and writes it into a fixed-size buffer allocated on the stack.
The parser does not enforce a maximum prefix length before performing the copy. Supplying a namespace prefix that exceeds the destination buffer overwrites adjacent stack memory, including saved return addresses and frame pointers. This corruption is classified under both [CWE-121: Stack-based Buffer Overflow] and [CWE-120: Classic Buffer Overflow].
Exploitation yields code execution in the context of the ONVIF service, which runs with elevated privileges on the embedded Linux firmware. Successful attackers gain full control of the camera, including its video stream, credentials, and network position.
Root Cause
The root cause is missing input validation on the XML namespace prefix length prior to an unbounded copy into a fixed-size stack buffer. The parser trusts attacker-controlled data from network input without applying a boundary check.
Attack Vector
The attack requires network adjacency, meaning the attacker must reach the camera's ONVIF endpoint on the same Layer 2 segment or routed local network. No authentication and no user interaction are required. An attacker sends a single crafted SOAP request containing an oversized XML namespace prefix to the ONVIF service to trigger stack corruption.
// No verified public proof-of-concept is available. The vulnerable behavior is
// triggered by SOAP requests structured similarly to the outline below, where
// the namespace prefix is expanded far beyond the fixed stack buffer size.
//
// POST /onvif/device_service HTTP/1.1
// Host: <camera-ip>
// Content-Type: application/soap+xml
//
// <s:Envelope xmlns:s="..." xmlns:AAAAAAAA...[oversized prefix]="...">
// <AAAAAAAA...:GetDeviceInformation/>
// </s:Envelope>
Detection Methods for CVE-2025-8065
Indicators of Compromise
- Unexpected inbound SOAP or ONVIF traffic to Tapo cameras from hosts other than the Tapo mobile app or authorized network video recorders
- Tapo cameras initiating outbound connections to unknown IP addresses or non-standard ports after receiving ONVIF traffic
- Camera reboots, video stream interruptions, or ONVIF service crashes coinciding with malformed SOAP requests
Detection Strategies
- Inspect ONVIF SOAP traffic on port 80, 2020, or vendor-specific ONVIF ports for XML namespace declarations with abnormally long prefix strings
- Alert on packet payloads containing repeated character sequences within xmlns: attributes that exceed typical prefix lengths of a few characters
- Correlate malformed SOAP requests with subsequent process crashes or unexpected outbound activity from IoT VLANs
Monitoring Recommendations
- Segment Tapo cameras onto a dedicated IoT VLAN and log all traffic crossing the segment boundary
- Enable NetFlow or packet capture on switches serving camera segments to retain evidence of ONVIF exploitation attempts
- Monitor firmware version reporting from each Tapo device to confirm patched builds are deployed
How to Mitigate CVE-2025-8065
Immediate Actions Required
- Update all Tapo C200 v3 and C520WS v2.6 devices to the latest firmware released by TP-Link via the TP-Link Tapo C200 Firmware Notes and TP-Link Tapo C520WS Firmware Notes
- Restrict network access to camera ONVIF endpoints so that only authorized management hosts can reach them
- Inventory all Tapo cameras in the environment and confirm firmware versions against the fixed release listed in the vendor advisory
Patch Information
TP-Link has published firmware updates and guidance addressing CVE-2025-8065. Refer to TP-Link FAQ #4849 for the vendor advisory and to the Tapo C200 v3 and C520WS release notes for the corresponding fixed firmware builds. Apply the updates through the Tapo mobile app or the device's local management interface.
Workarounds
- Block inbound traffic to camera ONVIF service ports at the network firewall or switch access control list until firmware is applied
- Disable ONVIF on the camera if the feature is not required by the deployed video management system
- Place cameras behind a network video recorder and prohibit direct client access to the camera management interface
# Example: restrict ONVIF access to a single management host on a Linux gateway
iptables -A FORWARD -p tcp -s <management-host-ip> -d <camera-ip> --dport 2020 -j ACCEPT
iptables -A FORWARD -p tcp -d <camera-ip> --dport 2020 -j DROP
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
