Null Pointer Dereference Vulnerability in Tapo C100 and C101 by TP-Link
CVE-2026-75618

7.1HIGH

What is CVE-2026-75618?

The Tapo C100 and C101 cameras by TP-Link contain a null pointer dereference vulnerability within their RTSP service. This flaw allows attackers on the same local network to send specifically crafted requests that cause the service to reference an invalid pointer. As a result, this can lead to the service crashing and the device rebooting. Attackers can exploit this vulnerability to disrupt ongoing video streaming processes, creating a denial-of-service condition that temporarily affects device functionality.

Affected Version(s)

Tapo C100 v5 0 < 1.5.4 Build 260528 Rel.11462n

Tapo C101 v5 0 < 1.5.4 Build 260528 Rel.11462n

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.