Description
Tapo C100/C101 V5 contains a null pointer dereference vulnerability in the RTSP service. An attacker on the local network can send specially crafted requests that cause the service to dereference an invalid pointer, resulting in a service crash and device reboot. Successful exploitation can disrupt live video streaming functionality and cause a temporary denial-of-service condition.
Published: 2026-08-19
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A null pointer dereference (CWE-476) in the RTSP service causes the service to crash and the device to reboot when a specially crafted request is received from a nearby attacker. The resulting denial of service interrupts live video streaming and renders the camera unusable until it restarts.

Affected Systems

TP-Link Systems Inc. Tapo C100 version 5 and Tapo C101 version 5 are affected. The vulnerability exists in devices running firmware v5 on both models and only applies to local‑network traffic targeting the RTSP service.

Risk and Exploitability

The CVSS score of 7.1 indicates high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires an attacker to send crafted packets to the RTSP port from the local network; no privileged access or public exposure is needed. The impact is a temporary denial of service for camera streaming, which could impact security monitoring or surveillance workflows.

Generated by OpenCVE AI on August 20, 2026 at 13:00 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware update for Tapo C100 and C101 available through the TP‑Link support site.
  • If a firmware update is pending or unavailable, disable the RTSP service via the camera’s web interface or block the RTSP port on the local network firewall.
  • Isolate cameras from critical network segments or limit local‑network access to trusted devices to prevent remote local attackers from reaching the RTSP interface.

Generated by OpenCVE AI on August 20, 2026 at 13:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 04 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Tp-link tapo C100
Tp-link tapo C100 Firmware
Tp-link tapo C101
Tp-link tapo C101 Firmware
CPEs cpe:2.3:h:tp-link:tapo_c100:5.0:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:tapo_c101:5.0:*:*:*:*:*:*:*
cpe:2.3:o:tp-link:tapo_c100_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:tp-link:tapo_c101_firmware:*:*:*:*:*:*:*:*
Vendors & Products Tp-link tapo C100
Tp-link tapo C100 Firmware
Tp-link tapo C101
Tp-link tapo C101 Firmware
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Thu, 20 Aug 2026 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Tp-link
Tp-link tapo C100 V5
Tp-link tapo C101 V5
Vendors & Products Tp-link
Tp-link tapo C100 V5
Tp-link tapo C101 V5

Wed, 19 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 18:45:00 +0000

Type Values Removed Values Added
Description Tapo C100/C101 V5 contains a null pointer dereference vulnerability in the RTSP service. An attacker on the local network can send specially crafted requests that cause the service to dereference an invalid pointer, resulting in a service crash and device reboot. Successful exploitation can disrupt live video streaming functionality and cause a temporary denial-of-service condition.
Title RTSP Null Pointer Dereference Denial-of-Service Vulnerability on TP-Link Tapo C100 and C101
Weaknesses CWE-476
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Tp-link Tapo C100 Tapo C100 Firmware Tapo C100 V5 Tapo C101 Tapo C101 Firmware Tapo C101 V5
cve-icon MITRE

Status: PUBLISHED

Assigner: TPLink

Published:

Updated: 2026-08-27T23:12:07.933Z

Reserved: 2026-08-18T00:01:49.092Z

Link: CVE-2026-75618

cve-icon Vulnrichment

Updated: 2026-08-19T19:32:54.864Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-19T19:17:24.630

Modified: 2026-09-04T17:21:20.550

Link: CVE-2026-75618

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T13:15:03Z

Weaknesses