← Back

CVE-2026-12760

nvd nist
Published: Jun 24, 2026Modified: Jun 29, 2026

JSON object

Loading...
7.1
Vector
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Show more
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: f23511db-6c3e-4e32-a477-6aa17d310630 (Secondary)

Description

A denial-of-service (DoS) vulnerability has been identified in Tapo C200 v3 in the network packet handling logic due to improper handling of IPv4 fragmented packets.  An unauthenticated adjacent attacker can send crafted packets to cause excessive resource consumption, leading to instability of the device.Successful exploitation can remotely trigger a temporary denial-of-service condition, causing the camera to become unresponsive and resulting in intermittent loss of video monitoring and recording.

Affected (11)

1 product
Tapo C200 Firmware
Configuration A
11 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Tp Link
Version 1.3.11 build_231115
Version 1.3.13 build_240327
Version 1.3.14 build_240513
Version 1.3.15 build_240715
Version 1.3.3 build_230228
Version 1.3.4 build_230424
Version 1.3.5 build_230717
Version 1.3.7 build_230920
Version 1.3.9 build_231019
Version 1.4.1 build_241212
Version 1.4.2 build_250313
Running on/withPlatform Versions
Tp Link
Tapo C200
Version 3

References (3)

Source: f23511db-6c3e-4e32-a477-6aa17d310630
Release Notes
Source: f23511db-6c3e-4e32-a477-6aa17d310630
Release Notes
Source: f23511db-6c3e-4e32-a477-6aa17d310630
Vendor Advisory

Timeline

No history available yet.