VYPR

Tapo C100

by TP-Link

CVEs (3)

  • CVE-2026-34118MedApr 2, 2026
    risk 0.42cvss 6.5epss 0.01

    A heap-based buffer overflow vulnerability was identified in TP-Link Tapo C100/C101 v5, C520WS v2.6 in the HTTP POST body parsing logic due to missing validation of remaining buffer capacity after dynamic allocation, due to insufficient boundary validation when handling…

  • CVE-2023-39610MedOct 31, 2023
    risk 0.42cvss 6.5epss 0.00

    An issue in TP-Link Tapo C100 v1.1.15 Build 211130 Rel.15378n(4555) and before allows attackers to cause a Denial of Service (DoS) via supplying a crafted web request.

  • CVE-2026-75619MedAug 19, 2026
    risk 0.37cvss 5.7epss 0.00

    Tapo C100/C101 V5 contains a heap-based buffer overflow vulnerability in the RTSP service. An authenticated attacker on the local network can send specially crafted RTSP frame data containing oversized length values, resulting in out-of-bounds heap writes. Successful…