Impact
An improper validation of encrypted credential data in the configuration service allows an attacker to send oversized ciphertext. The lack of bounds checking causes internal exception handling to fail, leading the device to crash or restart. This results in a temporary disruption of HTTPS management and monitoring until the service recovers, effectively denying access to legitimate administrators.
Affected Systems
TP-Link Systems Inc. Tapo C200 v5 is the only product affected as identified by the CNA.
Risk and Exploitability
The CVSS score of 7.1 indicates a substantial impact, and although EPSS data is unavailable, the flaw is not known to be exploited in the wild. The vulnerability is not listed in CISA KEV, suggesting no confirmed public exploits yet. An attacker with network access to the device could send the malformed payload remotely, triggering the crash. The risk is moderate, but the disruption to management services can be significant for operations that rely on continuous device control.
OpenCVE Enrichment