CVE-2026-75619
Received Received - Intake

Heap Overflow in Tapo C100/C101 V5 RTSP Service

Vulnerability report for CVE-2026-75619, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-19

Last updated on: 2026-08-19

Assigner: TPLink

Description

Tapo C100/C101 V5 contains a heap-based buffer overflow vulnerability in the RTSP service. An authenticated attacker on the local network can send specially crafted RTSP frame data containing oversized length values, resulting in out-of-bounds heap writes. Successful exploitation can crash the RTSP service and trigger a device reboot, resulting in a temporary denial-of-service condition.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-19
Last Modified
2026-08-19
Generated
2026-08-19
AI Q&A
2026-08-19
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
tp-link tapo_c100 c100_v5
tp-link tapo_c101 c101_v5

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-122 A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-75619 is a heap-based buffer overflow vulnerability in the RTSP service of Tapo C100 and C101 cameras running version V5 firmware. An authenticated attacker on the local network can exploit this by sending specially crafted RTSP frame data with oversized length values, causing out-of-bounds heap writes.

Detection Guidance

Detecting this vulnerability requires monitoring RTSP traffic for malformed packets with oversized length values. Use network sniffing tools like Wireshark to capture RTSP traffic and inspect packet lengths. Check device logs for crashes or unexpected reboots, which may indicate exploitation attempts.

Impact Analysis

Successful exploitation can crash the RTSP service and force the device to reboot, resulting in a temporary denial-of-service condition. This disrupts camera functionality until the device restarts.

Mitigation Strategies

Update the firmware of Tapo C100/C101 devices to version 1.5.4 Build 260528 Rel.11462n or later. Disable the RTSP service if not required. Restrict local network access to the device by configuring firewall rules to limit exposure.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-75619. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart