MEDIUM 6.9 NVD
CVE-2026-75619
Tapo C100/C101 V5 contains a heap-based buffer overflow vulnerability in the RTSP service. An authenticated attacker on the local network can send specially cra
Tapo
C100/C101 V5 contains a heap-based buffer overflow vulnerability in the RTSP
service. An authenticated attacker on the local network can send specially
crafted RTSP frame data containing oversized length values, resulting in
out-of-bounds heap writes.
Successful
exploitation can crash the RTSP service and trigger a device reboot, resulting
in a temporary denial-of-service condition.
References
- https://www.tp-link.com/en/support/download/tapo-c100/#Firmware-Release-Notes
- https://www.tp-link.com/us/support/download/tapo-c100/#Firmware-Release-Notes
- https://www.tp-link.com/us/support/download/tapo-c101/#Firmware-Release-Notes
- https://www.tp-link.com/us/support/faq/5251/
This medium severity vulnerability with a CVSS score of 6.9 was published on 2026-08-19 via NVD.
vulnfeed aggregates 11644 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.