An improper input validation vulnerability in the configuration service for processing encrypted credential data has been identified in Tapo C200 v5.  An attacker can send oversized crypted ciphertext values that may trigger exception handling failures, due to insufficient validation, causing the affected device to crash or restart. Successful exploitation may temporarily disrupt HTTPS management and monitoring functionality, resulting in a denial-of-service (DoS) condition until the service recovers.
History

Fri, 04 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Tp-link tapo C200
Tp-link tapo C200 Firmware
CPEs cpe:2.3:h:tp-link:tapo_c200:5.0:*:*:*:*:*:*:*
cpe:2.3:o:tp-link:tapo_c200_firmware:*:*:*:*:*:*:*:*
Vendors & Products Tp-link tapo C200
Tp-link tapo C200 Firmware
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Fri, 21 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Tp-link
Tp-link tapo C200 V5
Vendors & Products Tp-link
Tp-link tapo C200 V5

Tue, 18 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description An improper input validation vulnerability in the configuration service for processing encrypted credential data has been identified in Tapo C200 v5.  An attacker can send oversized crypted ciphertext values that may trigger exception handling failures, due to insufficient validation, causing the affected device to crash or restart. Successful exploitation may temporarily disrupt HTTPS management and monitoring functionality, resulting in a denial-of-service (DoS) condition until the service recovers.
Title Denial-of-Service via Oversized Encrypted Credential Input in TP-Link Tapo C200
Weaknesses CWE-20
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: TPLink

Published: 2026-08-18T21:25:11.118Z

Updated: 2026-08-20T15:36:48.337Z

Reserved: 2026-07-09T17:55:11.713Z

Link: CVE-2026-15316

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T22:16:49.367

Modified: 2026-09-04T17:26:04.617

Link: CVE-2026-15316

cve-icon Redhat

No data.