Improper Input Validation Vulnerability in Tapo C200 by TP-Link
CVE-2026-15316
7.1HIGH
What is CVE-2026-15316?
An improper input validation vulnerability exists in the configuration service of TP-Link's Tapo C200 v5, affecting its ability to process encrypted credential data. By sending oversized encrypted ciphertext values, an attacker may trigger exception handling failures due to inadequate validation, which can lead to device crashes or restarts. This exploitation could result in temporary disruptions of HTTPS management and monitoring functionalities, essentially causing a denial-of-service condition until the service is restored.
Affected Version(s)
Tapo C200 v5 0
References
CVSS V4
Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Thai Do (Lio) and Khoi Tran (KayTii) from OPSWAT
