Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-104945— Authenticated ONVIF PTZ Out-of-Bounds Stack Write Denial of Service in TP-Link Tapo C500

Quick assessment

Affected
TP-Link Systems Inc. Tapo C500 v2.0
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

TP-Link Tapo C500 v2.0 在其 ONVIF PTZ SOAP 处理程序中存在一个越界栈写入漏洞。已认证的 ONVIF 客户端可以提交过量与预设位置相关的元素,导致对固定大小的栈数组进行越界写入,从而引发受影响服务的崩溃。 成功利用该漏洞可使已认证的攻击者导致受影响服务崩溃,造成拒绝服务(DoS)状况。反复利用该漏洞会持续中断摄像头管理和与 PTZ(云台/镜头/变焦)相关的功能,直至服务恢复或重启。

CVSS 6.8 · Medium

Affected Version Matrix 1

VendorProduct Version RangeStatus
TP-Link Systems Inc. Tapo C500 v2.0 < 1.3.5 Build 260810 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-104945

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Authenticated ONVIF PTZ Out-of-Bounds Stack Write Denial of Service in TP-Link Tapo C500
Source: CVE Program / CVE List V5
Vulnerability Description
TP-Link Tapo C500 v2.0 contains an out-of-bounds stack write vulnerability in its ONVIF PTZ SOAP handlers. An authenticated ONVIF client can submit an excessive number of preset-related elements, causing writes beyond the bounds of fixed-size stack arrays and resulting in a crash of the affected service. Successful exploitation may allow an authenticated attacker to cause the affected service to crash, resulting in a denial-of-service condition. Repeated exploitation may repeatedly disrupt camera management and PTZ-related functionality until the service recovers or restarts.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
栈缓冲区溢出
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
TP-Link Systems Inc. Tapo C500 v2.0 0 ~ 1.3.5 Build 260810 -

II. Public POCs for CVE-2026-104945

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-104945

请登录查看更多情报信息。

Other References for CVE-2026-104945 (3)

IV. Related Vulnerabilities

V. Comments for CVE-2026-104945

No comments yet


Leave a comment