Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-9032— Unauthenticated Onboarding Connect NULL Pointer Dereference Denial of Service Vulnerability in TP-Link Tapo C120 & C200

Quick assessment

Affected
TP-Link Systems Inc. Tapo C200 V5
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Tapo C120 v1 和 C200 v5 在 HTTPS 引导连接请求解析器中存在空指针解引用漏洞。该接口在完成初始设置后无需身份验证即可访问,并且未对某些认证和加密参数组合下的密码字段是否存在进行校验,使得来自同一本地网络的恶意构造请求能够导致 HTTPS 服务崩溃。 成功利用该漏洞可能导致 HTTPS 管理功能暂时不可用。反复发送恶意构造的请求可能使拒绝服务状态持续存在,在某些情况下可能需要重启设备才能恢复。

CVSS 7.1 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-9032

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Unauthenticated Onboarding Connect NULL Pointer Dereference Denial of Service Vulnerability in TP-Link Tapo C120 & C200
Source: CVE Program / CVE List V5
Vulnerability Description
Tapo C120 v1 and C200 v5 contain a NULL pointer dereference in the HTTPS onboarding connect request parser.  The interface is reachable without authentication after initial setup and does not validate that a password field is present for certain authentication and encryption parameter combinations, allowing a malformed request from the same local network to crash the HTTPS service  Successful exploitation may temporarily make HTTPS management functions unavailable. Repeated malformed requests may sustain the denial-of-service condition, and recovery may in some cases require a device reboot.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
空指针解引用
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
TP-Link Systems Inc. Tapo C200 V5 0 ~ V5_1.4.6 Build 260709 Rel.27675n -
TP-Link Systems Inc. Tapo C120 V1 0 ~ V1_1.9.4 Build 260813 Rel.79754n -

II. Public POCs for CVE-2026-9032

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-9032

请登录查看更多情报信息。

Vendor Pages for CVE-2026-9032 (2)

Other References for CVE-2026-9032 (1)

Same Patch Batch · TP-Link Systems Inc. · 2026-10-01 · 6 CVEs total

CVE-2026-102369 8.7 HIGH Unauthenticated Remote Code Execution via MacTool Command Injection in TP-Link Tapo C120 &
CVE-2026-8618 7.7 HIGH Pre-Authentication Stack-based Buffer Overflow Remote Code Execution in TDDPv2 Subtype 0x9
CVE-2026-84682 7.7 HIGH TDDPv2 setProductVer Command Injection in Archer AX90
CVE-2026-78578 7.1 HIGH Unauthenticated do Method Onboarding Connect Allows Wi‑Fi Reconfiguration Denial of Servic
CVE-2026-78577 5.3 MEDIUM Unauthenticated Onboarding Scan Information Disclosure in TP-Link Tapo C120 & C200

IV. Related Vulnerabilities

V. Comments for CVE-2026-9032

No comments yet


Leave a comment