6.5

CVE-2026-75618

RTSP Null Pointer Dereference Denial-of-Service Vulnerability on TP-Link Tapo C100 and C101

Tapo C100/C101 V5 contains a null pointer dereference vulnerability in the RTSP service. An attacker on the local network can send specially crafted requests that cause the service to dereference an invalid pointer, resulting in a service crash and device reboot. Successful exploitation can disrupt live video streaming functionality and cause a temporary denial-of-service condition.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Tp-link ≫ Tapo C100 Firmware Version < 1.5.4
   Tp-link ≫ Tapo C100 Version 5.0
Tp-link ≫ Tapo C101 Firmware Version < 1.5.4
   Tp-link ≫ Tapo C101 Version 5.0
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.19% 0.093
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.5 2.8 3.6
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
f23511db-6c3e-4e32-a477-6aa17d310630 7.1 0 0
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE-476 NULL Pointer Dereference

The product dereferences a pointer that it expects to be valid but is NULL.

https://www.tp-link.com/us/support/download/tapo-c100/#Firmware-Release-Notes
Release Notes
https://www.tp-link.com/us/support/download/tapo-c101/#Firmware-Release-Notes
Release Notes
https://www.tp-link.com/en/support/download/tapo-c100/#Firmware-Release-Notes
Release Notes
https://www.tp-link.com/us/support/faq/5251/
Vendor Advisory