CVE-2026-1871

HIGH EPSS 22.1%
Published Jun 2, 20263w ago · Modified Jun 17, 20261w ago
7.1 CVSS 4.0
High
Find Similar
Published Jun 2, 2026 3w ago
Last Modified Jun 17, 2026 1w ago

Description

TP-Link Tapo C200 v5 contains a stack-based buffer overflow flaw in RTSP authentication handling due to improper validation of Authorization header field lengths, which can be triggered by a crafted authentication request. Successful exploitation causes the affected RTSP core service process to crash and triggers an automatic system reboot, resulting in a denial of service (DoS) condition. This prevents legitimate users from accessing the camera’s live video stream or management interface until the service restarts.

CVSS Details

Base Score
7.1
Exploitability
Impact
Vector string
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Attack Vector Adjacent
Attack Complexity Low
Privileges Required None
User Interaction None
Scope X

Threat Intelligence

EPSS Exploit Probability
22.1% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available

Weaknesses 1

CWE-121

Affected Products 11

VendorProductVersionRange
tp-linktapo_c200_firmware1.0.5any
tp-linktapo_c200_firmware1.0.12any
tp-linktapo_c200_firmware1.0.13any
tp-linktapo_c200_firmware1.0.17any
tp-linktapo_c200_firmware1.1.4any
tp-linktapo_c200_firmware1.1.8any
tp-linktapo_c200_firmware1.2.3any
tp-linktapo_c200_firmware1.3.1any
tp-linktapo_c200_firmware1.3.3any
tp-linktapo_c200_firmware1.3.5any
tp-linktapo_c2005any

References 4

  • tp-link.com https://www.tp-link.com/en/support/download/tapo-c200/v5/#Firmware-Release-Notes
    Release Notes
  • tp-link.com https://www.tp-link.com/kr/support/download/tapo-c200/#Firmware-Release-Notes
    Release Notes
  • tp-link.com https://www.tp-link.com/us/support/download/tapo-c200/v5/#Firmware-Release-Notes
    Release Notes
  • tp-link.com https://www.tp-link.com/us/support/faq/5113/
    Vendor Advisory

Remediation

No remediation data recorded yet

Check vendor advisories and the NVD entry for patch availability.