CVE Database
/

CVE-2026-1871

Back to search

CVE-2026-1871

Published: Jun 2, 2026

Modified: Jun 2, 2026

PUBLISHED

Description

TP-Link Tapo C200 v5 contains a stack-based buffer overflow flaw in RTSP authentication handling due to improper validation of Authorization header field lengths, which can be triggered by a crafted authentication request. Successful exploitation causes the affected RTSP core service process to crash and triggers an automatic system reboot, resulting in a denial of service (DoS) condition. This prevents legitimate users from accessing the camera’s live video stream or management interface until the service restarts.

VendorProductVersions

TP-Link Systems Inc.

Tapo C200 v5

affected
0 - < 1.4.4 Build 260527 Rel.28339n

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now