CVE-2026-9032

Summary

Tapo C120 v1 and C200 v5 contain a NULL pointer dereference in the HTTPS onboarding connect request parser.  The interface is reachable without authentication after initial setup and does not validate that a password field is present for certain authentication and encryption parameter combinations, allowing a malformed request from the same local network to crash the HTTPS service

 Successful exploitation may temporarily make HTTPS management functions unavailable. Repeated malformed requests may sustain the denial-of-service condition, and recovery may in some cases require a device reboot.

Affected Software

VendorProductVersion RangeStatus
TP-Link Systems Inc.Tapo C200 V50 < V5_1.4.6 Build 260709 Rel.27675naffected
TP-Link Systems Inc.Tapo C120 V10 < V1_1.9.4 Build 260813 Rel.79754naffected

Weaknesses

  • CWE-476: CWE-476 NULL pointer dereference

References