CVE-2026-75619

Summary

Tapo C100/C101 V5 contains a heap-based buffer overflow vulnerability in the RTSP service. An authenticated attacker on the local network can send specially crafted RTSP frame data containing oversized length values, resulting in out-of-bounds heap writes.

Successful exploitation can crash the RTSP service and trigger a device reboot, resulting in a temporary denial-of-service condition.

Affected Software

VendorProductVersion RangeStatus
TP-Link Systems Inc.Tapo C100 v50 < 1.5.4 Build 260528 Rel.11462naffected
TP-Link Systems Inc.Tapo C101 v50 < 1.5.4 Build 260528 Rel.11462naffected

Weaknesses

  • CWE-122: CWE-122 Heap-based buffer overflow

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References