TP-Link Tapo C500 v2.0 在其 ONVIF PTZ SOAP 处理程序中存在一个越界栈写入漏洞。已认证的 ONVIF 客户端可以提交过量与预设位置相关的元素,导致对固定大小的栈数组进行越界写入,从而引发受影响服务的崩溃。 成功利用该漏洞可使已认证的攻击者导致受影响服务崩溃,造成拒绝服务(DoS)状况。反复利用该漏洞会持续中断摄像头管理和与 PTZ(云台/镜头/变焦)相关的功能,直至服务恢复或重启。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| TP-Link Systems Inc. | Tapo C500 v2.0 | < 1.3.5 Build 260810 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| TP-Link Systems Inc. | Tapo C500 v2.0 | 0 ~ 1.3.5 Build 260810 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet