Null Pointer Dereference Vulnerability in Tapo C100 and C101 by TP-Link
CVE-2026-75618
7.1HIGH
Key Information:
- Vendor
Tp-link Systems Inc.
- Status
- Vendor
- CVE Published:
- 19 August 2026
What is CVE-2026-75618?
The Tapo C100 and C101 cameras by TP-Link contain a null pointer dereference vulnerability within their RTSP service. This flaw allows attackers on the same local network to send specifically crafted requests that cause the service to reference an invalid pointer. As a result, this can lead to the service crashing and the device rebooting. Attackers can exploit this vulnerability to disrupt ongoing video streaming processes, creating a denial-of-service condition that temporarily affects device functionality.
Affected Version(s)
Tapo C100 v5 0 < 1.5.4 Build 260528 Rel.11462n
Tapo C101 v5 0 < 1.5.4 Build 260528 Rel.11462n
