Executive brief
A security vulnerability has been found in the TP-Link Tapo C200 v3 home security camera. An attacker on the same local network can send specially crafted data packets to the camera, causing it to crash or become unresponsive. This results in a temporary loss of video monitoring and recording capabilities, potentially leaving the monitored area unobserved.
Technical details
A denial-of-service (DoS) vulnerability exists in the network packet handling logic of the TP-Link Tapo C200 v3 camera. The flaw is rooted in the improper handling of IPv4 fragmented packets (CWE-770), which allows for resource exhaustion. An unauthenticated attacker located on the same local network (adjacent) can transmit crafted fragmented packets to the device. Successful exploitation causes excessive resource consumption, leading to device instability and a temporary denial-of-service state where the camera stops responding to legitimate requests and ceases video recording. The issue is resolved in firmware version 1.4.4 Build 250922.
Affected products
- TP-Link Tapo C200 v3 before 1.4.4 Build 250922
Timeline
- 2026-06-24: disclosed
- 2026-06-24: advisory
- 2026-06-24: patched: Fixed in version 1.4.4 Build 250922