Tapo
C100/C101 V5 contains a heap-based buffer overflow vulnerability in the RTSP
service. An authenticated attacker on the local network can send specially
crafted RTSP frame data containing oversized length values, resulting in
out-of-bounds heap writes.
Successful
exploitation can crash the RTSP service and trigger a device reboot, resulting
in a temporary denial-of-service condition.
References
| Link | Resource |
|---|---|
| https://www.tp-link.com/en/support/download/tapo-c100/#Firmware-Release-Notes | Product Release Notes |
| https://www.tp-link.com/us/support/download/tapo-c100/#Firmware-Release-Notes | Product Release Notes |
| https://www.tp-link.com/us/support/download/tapo-c101/#Firmware-Release-Notes | Product Release Notes |
| https://www.tp-link.com/us/support/faq/5251/ | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2026-08-19 19:17
Updated : 2026-09-04 17:08
NVD link : CVE-2026-75619
Mitre link : CVE-2026-75619
CVE.ORG link : CVE-2026-75619
JSON object : View
Products Affected
tp-link
- tapo_c100_firmware
- tapo_c100
- tapo_c101
- tapo_c101_firmware
CWE
CWE-122
Heap-based Buffer Overflow
