VYPR

Tapo C101

by TP-Link

CVEs (2)

  • CVE-2026-75618HigAug 19, 2026
    risk 0.46cvss epss

    Tapo C100/C101 V5 contains a null pointer dereference vulnerability in the RTSP service. An attacker on the local network can send specially crafted requests that cause the service to dereference an invalid pointer, resulting in a service crash and device reboot. Successful…

  • CVE-2026-34118MedApr 2, 2026
    risk 0.42cvss 6.5epss 0.00

    A heap-based buffer overflow vulnerability was identified in TP-Link Tapo C100/C101 v5, C520WS v2.6 in the HTTP POST body parsing logic due to missing validation of remaining buffer capacity after dynamic allocation, due to insufficient boundary validation when handling…