Medium severity6.5NVD Advisory· Published Aug 19, 2026· Updated Sep 4, 2026
CVE-2026-75618
CVE-2026-75618
Description
Tapo C100/C101 V5 contains a null pointer dereference vulnerability in the RTSP service. An attacker on the local network can send specially crafted requests that cause the service to dereference an invalid pointer, resulting in a service crash and device reboot. Successful exploitation can disrupt live video streaming functionality and cause a temporary denial-of-service condition.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
4- www.tp-link.com/us/support/faq/5251/nvdVendor Advisory
- www.tp-link.com/en/support/download/tapo-c100/nvdRelease Notes
- www.tp-link.com/us/support/download/tapo-c100/nvdRelease Notes
- www.tp-link.com/us/support/download/tapo-c101/nvdRelease Notes
News mentions
1- TP-Link: Eight Vulnerabilities Disclosed, High-Severity Flaws Hit TL-MR6400 v7 RouterVypr Intelligence · Aug 21, 2026