TP-Link Tapo C200
cpe:2.3:h:tp-link:tapo_c200:*:*:*:*:*:*:*, +1 more
- < Tapo C200(US)_V3_1.4.5 Build 251104
A denial-of-service vulnerability has been identified in the Tapo C200 V3 camera model. The issue arises because the HTTPS server on this device does not properly validate the Content-Length header. This flaw can lead to an integer overflow, allowing an unauthenticated attacker on the same local network segment to send crafted HTTPS requests. These requests can trigger excessive memory allocation, causing the device to crash and become unresponsive.
Exploitation of this vulnerability causes the device to crash, leading to a denial-of-service condition where the camera becomes unresponsive.
Users are advised to check for updates on the Tapo Mobile Application to address this vulnerability. The latest firmware version can be downloaded from the TP-Link website.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.