CVE-2026-1871

TP-Link Tapo C200 v5 contains a stack-based buffer overflow flaw in RTSP authentication handling due to improper validation of Authorization header field lengths, which can be triggered by a crafted authentication request. Successful exploitation causes the affected RTSP core service process to crash and triggers an automatic system reboot, resulting in a denial of service (DoS) condition. This prevents legitimate users from accessing the camera’s live video stream or management interface until the service restarts.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:o:tp-link:tapo_c200_firmware:1.0.5:build_240327:*:*:*:*:*:*
cpe:2.3:o:tp-link:tapo_c200_firmware:1.0.12:build_240527:*:*:*:*:*:*
cpe:2.3:o:tp-link:tapo_c200_firmware:1.0.13:build_240619:*:*:*:*:*:*
cpe:2.3:o:tp-link:tapo_c200_firmware:1.0.17:build_240806:*:*:*:*:*:*
cpe:2.3:o:tp-link:tapo_c200_firmware:1.1.4:build_241219:*:*:*:*:*:*
cpe:2.3:o:tp-link:tapo_c200_firmware:1.1.8:build_250310:*:*:*:*:*:*
cpe:2.3:o:tp-link:tapo_c200_firmware:1.2.3:build_250610:*:*:*:*:*:*
cpe:2.3:o:tp-link:tapo_c200_firmware:1.3.1:build_250910:*:*:*:*:*:*
cpe:2.3:o:tp-link:tapo_c200_firmware:1.3.3:build_251119:*:*:*:*:*:*
cpe:2.3:o:tp-link:tapo_c200_firmware:1.3.5:build_260228:*:*:*:*:*:*
cpe:2.3:h:tp-link:tapo_c200:5:*:*:*:*:*:*:*

History

04 Jun 2026, 17:41

Type Values Removed Values Added
References () https://www.tp-link.com/en/support/download/tapo-c200/v5/#Firmware-Release-Notes - () https://www.tp-link.com/en/support/download/tapo-c200/v5/#Firmware-Release-Notes - Release Notes
References () https://www.tp-link.com/kr/support/download/tapo-c200/#Firmware-Release-Notes - () https://www.tp-link.com/kr/support/download/tapo-c200/#Firmware-Release-Notes - Release Notes
References () https://www.tp-link.com/us/support/download/tapo-c200/v5/#Firmware-Release-Notes - () https://www.tp-link.com/us/support/download/tapo-c200/v5/#Firmware-Release-Notes - Release Notes
References () https://www.tp-link.com/us/support/faq/5113/ - () https://www.tp-link.com/us/support/faq/5113/ - Vendor Advisory
CPE cpe:2.3:o:tp-link:tapo_c200_firmware:1.0.17:build_240806:*:*:*:*:*:*
cpe:2.3:o:tp-link:tapo_c200_firmware:1.3.1:build_250910:*:*:*:*:*:*
cpe:2.3:o:tp-link:tapo_c200_firmware:1.1.4:build_241219:*:*:*:*:*:*
cpe:2.3:o:tp-link:tapo_c200_firmware:1.1.8:build_250310:*:*:*:*:*:*
cpe:2.3:o:tp-link:tapo_c200_firmware:1.3.3:build_251119:*:*:*:*:*:*
cpe:2.3:o:tp-link:tapo_c200_firmware:1.2.3:build_250610:*:*:*:*:*:*
cpe:2.3:o:tp-link:tapo_c200_firmware:1.3.5:build_260228:*:*:*:*:*:*
cpe:2.3:h:tp-link:tapo_c200:5:*:*:*:*:*:*:*
cpe:2.3:o:tp-link:tapo_c200_firmware:1.0.5:build_240327:*:*:*:*:*:*
cpe:2.3:o:tp-link:tapo_c200_firmware:1.0.12:build_240527:*:*:*:*:*:*
cpe:2.3:o:tp-link:tapo_c200_firmware:1.0.13:build_240619:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
First Time Tp-link
Tp-link tapo C200
Tp-link tapo C200 Firmware

02 Jun 2026, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-02 17:16

Updated : 2026-06-04 17:41


NVD link : CVE-2026-1871

Mitre link : CVE-2026-1871

CVE.ORG link : CVE-2026-1871


JSON object : View

Products Affected

tp-link

  • tapo_c200
  • tapo_c200_firmware
CWE
CWE-121

Stack-based Buffer Overflow