Tapo C120 v1 和 C200 v5 在 HTTPS 引导连接请求解析器中存在空指针解引用漏洞。该接口在完成初始设置后无需身份验证即可访问,并且未对某些认证和加密参数组合下的密码字段是否存在进行校验,使得来自同一本地网络的恶意构造请求能够导致 HTTPS 服务崩溃。 成功利用该漏洞可能导致 HTTPS 管理功能暂时不可用。反复发送恶意构造的请求可能使拒绝服务状态持续存在,在某些情况下可能需要重启设备才能恢复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| TP-Link Systems Inc. | Tapo C200 V5 | 0 ~ V5_1.4.6 Build 260709 Rel.27675n | - |
|
| TP-Link Systems Inc. | Tapo C120 V1 | 0 ~ V1_1.9.4 Build 260813 Rel.79754n | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-102369 | 8.7 HIGH | Unauthenticated Remote Code Execution via MacTool Command Injection in TP-Link Tapo C120 & |
| CVE-2026-8618 | 7.7 HIGH | Pre-Authentication Stack-based Buffer Overflow Remote Code Execution in TDDPv2 Subtype 0x9 |
| CVE-2026-84682 | 7.7 HIGH | TDDPv2 setProductVer Command Injection in Archer AX90 |
| CVE-2026-78578 | 7.1 HIGH | Unauthenticated do Method Onboarding Connect Allows Wi‑Fi Reconfiguration Denial of Servic |
| CVE-2026-78577 | 5.3 MEDIUM | Unauthenticated Onboarding Scan Information Disclosure in TP-Link Tapo C120 & C200 |
No comments yet