CVE-2026-9032
Received Received - Intake

NULL Pointer Dereference in Tapo C120 and C200 HTTPS Parser

Vulnerability report for CVE-2026-9032, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: TPLink

Description

Tapo C120 v1 and C200 v5 contain a NULL pointer dereference in the HTTPS onboarding connect request parser.  The interface is reachable without authentication after initial setup and does not validate that a password field is present for certain authentication and encryption parameter combinations, allowing a malformed request from the same local network to crash the HTTPS service  Successful exploitation may temporarily make HTTPS management functions unavailable. Repeated malformed requests may sustain the denial-of-service condition, and recovery may in some cases require a device reboot.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
tapo c120 1
tapo c200 5
tp-link tapo_c120 v1.1.9.4
tp-link tapo_c200 v5.1.4.6

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-476 The product dereferences a pointer that it expects to be valid but is NULL.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a NULL pointer dereference in the HTTPS onboarding connect request parser of Tapo C120 v1 and C200 v5 devices. The issue occurs because the interface does not validate the presence of a password field for certain authentication and encryption parameter combinations. A malformed request from the same local network can crash the HTTPS service.

Detection Guidance

Detecting this vulnerability requires monitoring for malformed HTTPS onboarding connect requests targeting Tapo C120 v1 or C200 v5 devices. Check network logs for repeated crashes of the HTTPS service on these devices. Use packet capture tools like tcpdump to inspect local network traffic for malformed requests to the HTTPS interface.

Impact Analysis

Exploitation may temporarily make HTTPS management functions unavailable. Repeated malformed requests could sustain a denial-of-service condition, and recovery might require a device reboot in some cases.

Compliance Impact

This vulnerability may temporarily disrupt HTTPS management functions, potentially affecting access to security controls and audit logs. For GDPR, this could impact data integrity and availability requirements. For HIPAA, it may compromise the confidentiality and integrity of protected health information if management functions are disrupted.

Mitigation Strategies

Isolate affected Tapo C120 v1 or C200 v5 devices from untrusted networks. Apply firmware updates if available. Block or restrict access to the HTTPS management interface from local networks until a patch is applied. Monitor device stability and reboot if the HTTPS service crashes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-9032. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart