Executive brief
The TP-Link Tapo C200 v5 security camera is vulnerable to a flaw that allows an attacker to crash the device. By sending a specially crafted authentication request, an attacker can force the camera to reboot, causing a temporary loss of live video monitoring and access to the management interface. This disruption persists until the device completes its automatic restart process.
Technical details
A stack-based buffer overflow vulnerability exists in the RTSP core service of the TP-Link Tapo C200 v5. The flaw is caused by improper validation of the length of the 'Authorization' header field during RTSP authentication. An attacker on the same local network can trigger this overflow by sending a crafted authentication request. Successful exploitation results in the RTSP process crashing, which triggers an automatic system-wide reboot, effectively creating a denial of service (DoS) condition for the camera's primary functions. Firmware updates are typically available through the Tapo mobile application.
Affected products
- TP-Link Tapo C200 v5
Timeline
- 2026-06-02: disclosed: CVE published by TP-Link via NVD