CVE-2026-75619: TP-Link Tapo c100 Firmware

Medium severity, CVSS 5.7. EPSS: 0.4% chance of exploitation in the next 30 days.

Tapo C100/C101 V5 contains a heap-based buffer overflow vulnerability in the RTSP service. An authenticated attacker on the local network can send specially crafted RTSP frame data containing oversized length values, resulting in out-of-bounds heap writes. Successful exploitation can crash the RTSP service and trigger a device reboot, resulting in a temporary denial-of-service condition.

Affected products

  • TP-Link Tapo c100 Firmware: before 1.5.4 (fixed in 1.5.4)
  • TP-Link Tapo c101 Firmware: before 1.5.4 (fixed in 1.5.4)

Published 2026-08-19. Last modified 2026-09-04.