← Back

Tapo C100 Firmware

tapo_c100_firmware

Vendor: Tp Link • 4 CVEs

CVEs (4)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Tp Link
2Tapo C100 Firmware
Tapo C101 Firmware
Sep 4, 2026
Aug 19, 2026
6.9 MEDIUM· v4
5.7 MEDIUM· v3
N/A· v2
Tapo C100/C101 V5 contains a heap-based buffer overflow vulnerability in the RTSP service. An authenticated attacker on the local network can send specially crafted RTSP frame data containing oversized length values, res...Show more
Tapo C100/C101 V5 contains a heap-based buffer overflow vulnerability in the RTSP service. An authenticated attacker on the local network can send specially crafted RTSP frame data containing oversized length values, resulting in out-of-bounds heap writes. Successful exploitation can crash the RTSP service and trigger a device reboot, resulting in a temporary denial-of-service condition.Show less
1Tp Link
2Tapo C100 Firmware
Tapo C101 Firmware
Sep 4, 2026
Aug 19, 2026
7.1 HIGH· v4
6.5 MEDIUM· v3
N/A· v2
Tapo C100/C101 V5 contains a null pointer dereference vulnerability in the RTSP service. An attacker on the local network can send specially crafted requests that cause the service to dereference an invalid pointer, resu...Show more
Tapo C100/C101 V5 contains a null pointer dereference vulnerability in the RTSP service. An attacker on the local network can send specially crafted requests that cause the service to dereference an invalid pointer, resulting in a service crash and device reboot. Successful exploitation can disrupt live video streaming functionality and cause a temporary denial-of-service condition.Show less
1Tp Link
1Tapo C100 Firmware
Jun 17, 2026
Oct 31, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An issue in TP-Link Tapo C100 v1.1.15 Build 211130 Rel.15378n(4555) and before allows attackers to cause a Denial of Service (DoS) via supplying a crafted web request.
1Tp Link
15Kc200 Firmware
Kc300s2 FirmwareKc310s2 Firmware+12 more
Jun 17, 2026
Apr 1, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
TP-Link cloud cameras through 2020-02-09 allow remote attackers to bypass authentication and obtain sensitive information via vectors involving a Wi-Fi session with GPS enabled, aka CNVD-2020-04855.