TP-Link Tapo
C500 v2.0 contains an out-of-bounds stack write vulnerability in its ONVIF PTZ
SOAP handlers. An authenticated ONVIF client can submit an excessive number of
preset-related elements, causing writes beyond the bounds of fixed-size stack
arrays and resulting in a crash of the affected service.
Successful
exploitation may allow an authenticated attacker to cause the affected service
to crash, resulting in a denial-of-service condition. Repeated exploitation may
repeatedly disrupt camera management and PTZ-related functionality until the
service recovers or restarts.
CISA SSVCTrack at every mission impact level.
No fix is confirmed yet. Restrict network exposure of the affected system or apply the vendor's mitigation within your standard update timelines, and watch the vendor's advisory for the fix.
Exploitation none (CISA Vulnrichment) · Automatable no (CISA Vulnrichment) · Technical impact partial (CISA Vulnrichment). Mission impact is CISA's Mission & Well-being decision point, and only you can judge it: high means the affected system is essential to your organisation's mission, or its compromise could cause irreversible harm to people. CISA's decision table