HIGH 7.1 NVD

CVE-2026-9032

Tapo C120 v1 and C200 v5 contain a NULL pointer dereference in the HTTPS onboarding connect request parser.  The interface is reachable without authentication a

Tapo C120 v1 and C200 v5 contain a NULL pointer dereference in the HTTPS onboarding connect request parser.  The interface is reachable without authentication after initial setup and does not validate that a password field is present for certain authentication and encryption parameter combinations, allowing a malformed request from the same local network to crash the HTTPS service  Successful exploitation may temporarily make HTTPS management functions unavailable. Repeated malformed requests may sustain the denial-of-service condition, and recovery may in some cases require a device reboot.

References

Published: 2026-10-01 · Source: NVD · Feed updated: 2026-10-01
This high severity vulnerability with a CVSS score of 7.1 was published on 2026-10-01 via NVD.
vulnfeed aggregates 9446 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.