CVE-2026-15316
Denial-of-Service via Oversized Encrypted Credential Input in TP-Link Tapo C200
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
An improper input validation vulnerability in the configuration service for processing encrypted credential data has been identified in Tapo C200 v5.ย An attacker can send oversized crypted ciphertext values that may trigger exception handling failures, due to insufficient validation, causing the affected device to crash or restart. Successful exploitation may temporarily disrupt HTTPS management and monitoring functionality, resulting in a denial-of-service (DoS) condition until the service recovers.
| CWE | CWE-20 |
| Vendor | tp-link systems inc. |
| Product | tapo c200 v5 |
| Published | Aug 18, 2026 |
Stay Ahead of the Next One
Get instant alerts for tp-link systems inc. tapo c200 v5
Be the first to know when new unknown vulnerabilities affecting tp-link systems inc. tapo c200 v5 are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
TP-Link Systems Inc. / Tapo C200 v5
0 < V5_1.4.6 Build 260709 Rel.27675n
References
Credits
Thai Do (Lio) and Khoi Tran (KayTii) from OPSWAT