Vulnerability record · CVE-2026-75619 · published 19 August 2026
CVE-2026-75619: Tp-link tapo c100 firmware heap-based buffer overflow vulnerability
Tp Link · Tapo C100 Firmware
Tapo C100/C101 V5 contains a heap-based buffer overflow vulnerability in the RTSP service. An authenticated attacker on the local network can send specially crafted RTSP frame data containing oversized length values, resulting in out-of-bounds heap writes. Successful exploitation can crash the RTSP service and trigger a device reboot, resulting in a temporary denial-of-service condition.
Description
Tapo C100/C101 V5 contains a heap-based buffer overflow vulnerability in the RTSP service. An authenticated attacker on the local network can send specially crafted RTSP frame data containing oversized length values, resulting in out-of-bounds heap writes. Successful exploitation can crash the RTSP service and trigger a device reboot, resulting in a temporary denial-of-service condition.
CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.tp-link.com/en/support/download/tapo-c100/#Firmware-Release-Notes | ProductRelease Notes |
| https://www.tp-link.com/us/support/download/tapo-c100/#Firmware-Release-Notes | ProductRelease Notes |
| https://www.tp-link.com/us/support/download/tapo-c101/#Firmware-Release-Notes | ProductRelease Notes |
| https://www.tp-link.com/us/support/faq/5251/ | Vendor Advisory |
Track CVE-2026-75619 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2026-75619), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.