Tapo C100/C101 V5 的 RTSP 服务中存在一个基于堆的缓冲区溢出漏洞。位于本地网络中的已认证攻击者可以发送包含超大长度值的专业构造的 RTSP 帧数据,导致对堆内存的越界写入。 成功利用该漏洞可导致 RTSP 服务崩溃并触发设备重启,从而造成暂时性的拒绝服务(DoS)状态。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| TP-Link Systems Inc. | Tapo C100 v5 | < 1.5.4 Build 260528 Rel.11462n |
affected |
| TP-Link Systems Inc. | Tapo C101 v5 | < 1.5.4 Build 260528 Rel.11462n |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| TP-Link Systems Inc. | Tapo C100 v5 | 0 ~ 1.5.4 Build 260528 Rel.11462n | - |
|
| TP-Link Systems Inc. | Tapo C101 v5 | 0 ~ 1.5.4 Build 260528 Rel.11462n | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-75616 | 8.5 HIGH | Command Injection in Router Web Management Interface |
| CVE-2026-75618 | 7.1 HIGH | RTSP Null Pointer Dereference Denial-of-Service Vulnerability on TP-Link Tapo C100 and C10 |
| CVE-2026-8619 | 7.1 HIGH | Unauthenticated Denial-of-Service Vulnerability in HTTP Service in TP-Link TL-MR100, TL-MR |
No comments yet