GHSA-gq3v-7fcg-vgjcHigh
Tapo C120 v1 and C200 v5 contain a NULL pointer dereference in the HTTPS onboarding connect...
🔗 CVE IDs covered (1)
📋 Description
Tapo C120 v1 and C200 v5 contain a NULL pointer dereference in the HTTPS onboarding connect request parser. The interface is reachable without authentication after initial setup and does not validate that a password field is present for certain authentication and encryption parameter combinations, allowing a malformed request from the same local network to crash the HTTPS service
Successful exploitation may temporarily make HTTPS management functions unavailable. Repeated malformed requests may sustain the denial-of-service condition, and recovery may in some cases require a device reboot.
🔗 References (7)
- https://nvd.nist.gov/vuln/detail/CVE-2026-9032
- https://www.tp-link.com/en/support/download/tapo-c120/v1.26/#Firmware-Release-Notes
- https://www.tp-link.com/en/support/download/tapo-c200/v5/#Firmware-Release-Notes
- https://www.tp-link.com/us/support/download/tapo-c120/v1.26/#Firmware-Release-Notes
- https://www.tp-link.com/us/support/download/tapo-c200/v5/#Firmware-Release-Notes
- https://www.tp-link.com/us/support/faq/5321
- https://github.com/advisories/GHSA-gq3v-7fcg-vgjc