CVE-2026-15316 PUBLISHED

Denial-of-Service via Oversized Encrypted Credential Input in TP-Link Tapo C200

Assigner: TPLink
Reserved: 09.07.2026 Published: 18.08.2026 Updated: 18.08.2026

An improper input validation vulnerability in the configuration service for processing encrypted credential data has been identified in Tapo C200 v5.  An attacker can send oversized crypted ciphertext values that may trigger exception handling failures, due to insufficient validation, causing the affected device to crash or restart.

Successful exploitation may temporarily disrupt HTTPS management and monitoring functionality, resulting in a denial-of-service (DoS) condition until the service recovers.

Metrics

CVSS Vector: CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
CVSS Score: 7.1

Product Status

Vendor TP-Link Systems Inc.
Product Tapo C200 v5
Versions Default: unaffected
  • affected from 0 to V5_1.4.6 Build 260709 Rel.27675n (excl.)

Credits

  • Thai Do (Lio) and Khoi Tran (KayTii) from OPSWAT finder

References

Problem Types

  • CWE-20 Improper input validation CWE

Impacts

  • CAPEC-24 Filter Failure through Buffer Overflow