CVE-2026-1871
TP-Link Tapo C200 v5 contains a stack-based buffer overflow flaw in RTSP authentication handling due to improper validation of Authorization
CVSS
6.5
Medio
EPSS
0.3%
p23
KEV
—
Exploit Today
7
0-100
Publicado: 2 jun 2026 · Última mod.: 22 jul 2026 · CWE-121
TP-Link Tapo C200 v5 contains a stack-based buffer overflow flaw in RTSP authentication handling due to improper validation of Authorization header field lengths, which can be triggered by a crafted authentication request. Successful exploitation causes the affected RTSP core service process to crash and triggers an automatic system reboot, resulting in a denial of service (DoS) condition. This prevents legitimate users from accessing the camera’s live video stream or management interface until the service restarts.
- www.tp-link.comhttps://www.tp-link.com/en/support/download/tapo-c200/v5/#Firmware-Release-Notes
- www.tp-link.comhttps://www.tp-link.com/kr/support/download/tapo-c200/#Firmware-Release-Notes
- www.tp-link.comhttps://www.tp-link.com/us/support/download/tapo-c200/v5/#Firmware-Release-Notes
- www.tp-link.comhttps://www.tp-link.com/us/support/faq/5113/