CVE-2026-15316
7.1
Vector
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow more
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: f23511db-6c3e-4e32-a477-6aa17d310630 (Secondary)
Description
An improper input
validation vulnerability in the configuration service for processing encrypted
credential data has been identified in Tapo C200 v5. An attacker can send oversized crypted
ciphertext values that may trigger exception handling failures, due to insufficient
validation, causing the affected device to crash or restart.
Successful
exploitation may temporarily disrupt HTTPS management and monitoring
functionality, resulting in a denial-of-service (DoS) condition until the
service recovers.
Affected (1)
Products: Tp Link: Tapo C200 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.4.6 |
| Running on/with | Platform Versions |
|---|---|
Tp Link Tapo C200 | Version 5.0 |
References (3)
Source: f23511db-6c3e-4e32-a477-6aa17d310630
ProductRelease Notes
Source: f23511db-6c3e-4e32-a477-6aa17d310630
ProductRelease Notes
Source: f23511db-6c3e-4e32-a477-6aa17d310630
Vendor Advisory
Timeline
No history available yet.