CVE-2026-1871: TP-Link Tapo c200 Firmware

Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.

TP-Link Tapo C200 v5 contains a stack-based buffer overflow flaw in RTSP authentication handling due to improper validation of Authorization header field lengths, which can be triggered by a crafted authentication request. Successful exploitation causes the affected RTSP core service process to crash and triggers an automatic system reboot, resulting in a denial of service (DoS) condition. This prevents legitimate users from accessing the camera’s live video stream or management interface until the service restarts.

Affected products

  • TP-Link Tapo c200 Firmware: version 1.0.5 only; version 1.0.12 only; version 1.0.13 only; version 1.0.17 only; version 1.1.4 only; version 1.1.8 only; …

Published 2026-06-02. Last modified 2026-07-22.