CVE-2026-75619

Tapo C100/C101 V5 contains a heap-based buffer overflow vulnerability in the RTSP service. An authenticated attacker on the local network can send specially crafted RTSP frame data containing oversized length values, resulting in out-of-bounds heap writes. Successful exploitation can crash the RTSP service and trigger a device reboot, resulting in a temporary denial-of-service condition.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:tp-link:tapo_c100_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:tapo_c100:5.0:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:tp-link:tapo_c101_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:tapo_c101:5.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-08-19 19:17

Updated : 2026-09-04 17:08


NVD link : CVE-2026-75619

Mitre link : CVE-2026-75619

CVE.ORG link : CVE-2026-75619


JSON object : View

Products Affected

tp-link

  • tapo_c100_firmware
  • tapo_c100
  • tapo_c101
  • tapo_c101_firmware
CWE
CWE-122

Heap-based Buffer Overflow