Tapo C120 and C200 Devices Vulnerable to NULL Pointer Dereference Issue
CVE-2026-9032
7.1HIGH
Key Information:
- Vendor
Tp-link Systems Inc.
- Status
- Vendor
- CVE Published:
- 1 October 2026
What is CVE-2026-9032?
The Tapo C120 and C200 devices by TP-Link exhibit a NULL pointer dereference vulnerability within their HTTPS onboarding connect request parser. This error occurs due to a lack of authentication validation after initial device setup, allowing unauthenticated access. In this scenario, if a specific malformed request is sent from within the same local network, it can lead to a denial-of-service condition on the HTTPS management functions. Repeated attempts to exploit this vulnerability can cause persistent disruption, potentially necessitating a device reboot for recovery.
Affected Version(s)
Tapo C120 V1 0
Tapo C200 V5 0
References
CVSS V4
Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Thai Do (Lio) and Khoi Tran (KayTii) from OPSWAT
