Tapo C120 and C200 Devices Vulnerable to NULL Pointer Dereference Issue
CVE-2026-9032

7.1HIGH

What is CVE-2026-9032?

The Tapo C120 and C200 devices by TP-Link exhibit a NULL pointer dereference vulnerability within their HTTPS onboarding connect request parser. This error occurs due to a lack of authentication validation after initial device setup, allowing unauthenticated access. In this scenario, if a specific malformed request is sent from within the same local network, it can lead to a denial-of-service condition on the HTTPS management functions. Repeated attempts to exploit this vulnerability can cause persistent disruption, potentially necessitating a device reboot for recovery.

Affected Version(s)

Tapo C120 V1 0

Tapo C200 V5 0

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Thai Do (Lio) and Khoi Tran (KayTii) from OPSWAT
.