MEDIUM 6.8 NVD
CVE-2026-104945
TP-Link Tapo C500 v2.0 contains an out-of-bounds stack write vulnerability in its ONVIF PTZ SOAP handlers. An authenticated ONVIF client can submit an excessive
TP-Link Tapo
C500 v2.0 contains an out-of-bounds stack write vulnerability in its ONVIF PTZ
SOAP handlers. An authenticated ONVIF client can submit an excessive number of
preset-related elements, causing writes beyond the bounds of fixed-size stack
arrays and resulting in a crash of the affected service.
Successful
exploitation may allow an authenticated attacker to cause the affected service
to crash, resulting in a denial-of-service condition. Repeated exploitation may
repeatedly disrupt camera management and PTZ-related functionality until the
service recovers or restarts.
References
- https://www.tp-link.com/en/support/download/tapo-c500/#Firmware-Release-Notes
- https://www.tp-link.com/us/support/download/tapo-c500/#Firmware-Release-Notes
- https://www.tp-link.com/us/support/faq/5327/
This medium severity vulnerability with a CVSS score of 6.8 was published on 2026-10-06 via NVD.
vulnfeed aggregates 9512 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.