Successful exploitation causes the affected RTSP core service process to crash and triggers an automatic system reboot, resulting in a denial of service (DoS) condition. This prevents legitimate users from accessing the camera’s live video stream or management interface until the service restarts.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 03 Jun 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tp-link
Tp-link tapo C200 V5 |
|
| Vendors & Products |
Tp-link
Tp-link tapo C200 V5 |
|
| Metrics |
ssvc
|
Tue, 02 Jun 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | TP-Link Tapo C200 v5 contains a stack-based buffer overflow flaw in RTSP authentication handling due to improper validation of Authorization header field lengths, which can be triggered by a crafted authentication request. Successful exploitation causes the affected RTSP core service process to crash and triggers an automatic system reboot, resulting in a denial of service (DoS) condition. This prevents legitimate users from accessing the camera’s live video stream or management interface until the service restarts. | |
| Title | Authenticated Stack-based Buffer Overflow in RTSP Authentication of Tapo C200 | |
| Weaknesses | CWE-121 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: TPLink
Published:
Updated: 2026-06-02T18:24:54.391Z
Reserved: 2026-02-04T00:03:47.430Z
Link: CVE-2026-1871
Updated: 2026-06-02T18:21:30.840Z
Status : Awaiting Analysis
Published: 2026-06-02T17:16:26.967
Modified: 2026-06-02T17:19:15.030
Link: CVE-2026-1871
No data.
OpenCVE Enrichment
Updated: 2026-06-02T20:50:51Z