CVE-2026-75618

Summary

Tapo C100/C101 V5 contains a null pointer dereference vulnerability in the RTSP service. An attacker on the local network can send specially crafted requests that cause the service to dereference an invalid pointer, resulting in a service crash and device reboot. Successful exploitation can disrupt live video streaming functionality and cause a temporary denial-of-service condition.

Affected Software

VendorProductVersion RangeStatus
TP-Link Systems Inc.Tapo C100 v50 < 1.5.4 Build 260528 Rel.11462naffected
TP-Link Systems Inc.Tapo C101 v50 < 1.5.4 Build 260528 Rel.11462naffected

Weaknesses

  • CWE-476: CWE-476 NULL pointer dereference

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References