Tapo C100/C101 V5 设备的 RTSP 服务存在一个空指针解引用漏洞。局域网内的攻击者可以通过发送精心构造的请求,导致服务解引用无效指针,从而引发服务崩溃及设备重启。成功利用该漏洞将中断实时视频流功能,造成临时性的拒绝服务(DoS)状态。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| TP-Link Systems Inc. | Tapo C100 v5 | < 1.5.4 Build 260528 Rel.11462n |
affected |
| TP-Link Systems Inc. | Tapo C101 v5 | < 1.5.4 Build 260528 Rel.11462n |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| TP-Link Systems Inc. | Tapo C100 v5 | 0 ~ 1.5.4 Build 260528 Rel.11462n | - |
|
| TP-Link Systems Inc. | Tapo C101 v5 | 0 ~ 1.5.4 Build 260528 Rel.11462n | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-75616 | 8.5 HIGH | Command Injection in Router Web Management Interface |
| CVE-2026-8619 | 7.1 HIGH | Unauthenticated Denial-of-Service Vulnerability in HTTP Service in TP-Link TL-MR100, TL-MR |
| CVE-2026-75619 | 6.9 MEDIUM | RTSP Heap Buffer Overflow Denial-of-Service Vulnerability on TP-Link Tapo C100 and C101 |
No comments yet