TP-Link Tapo C220
cpe:2.3:h:tp-link:tapo_c200_v1:*:*:*:*:*:*:*
- < 1.4.2 Build 251112
A denial-of-service vulnerability has been identified in TP-Link Tapo C220 v1 and C520WS v2 cameras. The issue arises in the HTTP parser, which improperly manages requests with excessively long URL paths. This mismanagement leads to a crash and an automatic restart of the camera service. An unauthenticated attacker can exploit this vulnerability to cause repeated service disruptions, forcing the camera to reboot and temporarily unavailable.
Exploitation of this vulnerability causes the camera service to crash, followed by an automatic restart. However, repeated exploitation can keep the service unavailable for an extended period.
Users are advised to update to the latest firmware version. The updated firmware for the Tapo C220 v1 can be downloaded from the TP-Link website. For the Tapo C520WS v2, the latest firmware is also available on the TP-Link website.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.