Impact
The vulnerability resides in the RTSP service of the Tapo C100 and C101 V5 firmware, allowing an authenticated local network attacker to send RTSP frames with oversized length fields. This causes out‑of‑bounds heap writes, which can crash the RTSP service and trigger a device reboot, resulting in a temporary denial‑of‑service condition. The flaw is a classic heap-based buffer overflow (CWE-122).
Affected Systems
TP‑Link Systems Inc. Tapo C100 v5 and Tapo C101 v5 are impacted. The issue affects only the RTSP service on these devices and requires an authenticated session on the local network.
Risk and Exploitability
The CVSS score of 6.9 classifies the exploit as moderate. Exploitation requires local network access and valid credentials; no publicly accessible path is documented. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, indicating a lower likelihood of widespread exploitation at this time. However, once a device is compromised locally, an attacker can achieve a denial‑of‑service outcome by forcing a reboot.
OpenCVE Enrichment