An improper input
validation vulnerability in the configuration service for processing encrypted
credential data has been identified in Tapo C200 v5. An attacker can send oversized crypted
ciphertext values that may trigger exception handling failures, due to insufficient
validation, causing the affected device to crash or restart.
Successful
exploitation may temporarily disrupt HTTPS management and monitoring
functionality, resulting in a denial-of-service (DoS) condition until the
service recovers.
References
| Link | Resource |
|---|---|
| https://www.tp-link.com/en/support/download/tapo-c200/v5/ | Product Release Notes |
| https://www.tp-link.com/us/support/download/tapo-c200/v5/ | Product Release Notes |
| https://www.tp-link.com/us/support/faq/5248/ | Vendor Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
History
No history.
Information
Published : 2026-08-18 22:16
Updated : 2026-09-04 17:26
NVD link : CVE-2026-15316
Mitre link : CVE-2026-15316
CVE.ORG link : CVE-2026-15316
JSON object : View
Products Affected
tp-link
- tapo_c200
- tapo_c200_firmware
CWE
CWE-20
Improper Input Validation
