VYPR

Tapo C500

by TP-Link

CVEs (2)

  • CVE-2026-104944HigOct 6, 2026
    risk 0.46cvss —epss —

    TP-Link Tapo C500 v2.0 contains an out-of-bounds function-pointer dispatch in its TDP (TP-Link Device Protocol) daemon. A single unauthenticated UDP datagram can cause an invalid indirect call, crashing the main service and resulting in a denial-of-service condition. …

  • CVE-2026-104945MedOct 6, 2026
    risk 0.44cvss —epss —

    TP-Link Tapo C500 v2.0 contains an out-of-bounds stack write vulnerability in its ONVIF PTZ SOAP handlers. An authenticated ONVIF client can submit an excessive number of preset-related elements, causing writes beyond the bounds of fixed-size stack arrays and resulting in a…