Tapo
C100/C101 V5 contains a heap-based buffer overflow vulnerability in the RTSP
service. An authenticated attacker on the local network can send specially
crafted RTSP frame data containing oversized length values, resulting in
out-of-bounds heap writes.
Successful
exploitation can crash the RTSP service and trigger a device reboot, resulting
in a temporary denial-of-service condition.
Attack Parameters
Impact Assessment
CVSS Vector v4.0
Weakness Type (CWE)
Vulnerable Products 4
| Configuration | From (including) | Up to (excluding) |
|---|---|---|
|
Tp-Link Tapo_C100_Firmware
cpe:2.3:o:tp-link:tapo_c100_firmware:*:*:*:*:*:*:*:*
|
— |
1.5.4
|
|
Tp-Link Tapo_C100
cpe:2.3:h:tp-link:tapo_c100:5.0:*:*:*:*:*:*:*
|
— | — |
|
Tp-Link Tapo_C101_Firmware
cpe:2.3:o:tp-link:tapo_c101_firmware:*:*:*:*:*:*:*:*
|
— |
1.5.4
|
|
Tp-Link Tapo_C101
cpe:2.3:h:tp-link:tapo_c101:5.0:*:*:*:*:*:*:*
|
— | — |