Heap-Based Buffer Overflow Vulnerability in Tapo C100/C101 by TP-Link
CVE-2026-75619
6.9MEDIUM
Key Information:
- Vendor
Tp-link Systems Inc.
- Status
- Vendor
- CVE Published:
- 19 August 2026
What is CVE-2026-75619?
The Tapo C100 and C101 devices from TP-Link are susceptible to a heap-based buffer overflow vulnerability that arises in their RTSP service. This flaw allows an authenticated attacker within the local network to transmit specially crafted RTSP frame data containing oversized length values. Such actions lead to out-of-bounds write operations in the heap memory, which can cause the RTSP service to crash and trigger an unexpected device reboot, potentially leading to a temporary denial-of-service condition. Users are advised to apply relevant patches immediately to mitigate this risk.
Affected Version(s)
Tapo C100 v5 0 < 1.5.4 Build 260528 Rel.11462n
Tapo C101 v5 0 < 1.5.4 Build 260528 Rel.11462n
