CVE-2026-75618

Tapo C100/C101 V5 contains a null pointer dereference vulnerability in the RTSP service. An attacker on the local network can send specially crafted requests that cause the service to dereference an invalid pointer, resulting in a service crash and device reboot. Successful exploitation can disrupt live video streaming functionality and cause a temporary denial-of-service condition.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:tp-link:tapo_c100_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:tapo_c100:5.0:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:tp-link:tapo_c101_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:tapo_c101:5.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-08-19 19:17

Updated : 2026-09-04 17:21


NVD link : CVE-2026-75618

Mitre link : CVE-2026-75618

CVE.ORG link : CVE-2026-75618


JSON object : View

Products Affected

tp-link

  • tapo_c100_firmware
  • tapo_c100
  • tapo_c101
  • tapo_c101_firmware
CWE
CWE-476

NULL Pointer Dereference