TP-Link Tapo C220
cpe:2.3:h:tp-link:tapo_c200_v1:*:*:*:*:*:*:*
- < 1.4.2 Build 251112
A denial-of-service vulnerability has been identified in the TP-Link Tapo C220 v1 and Tapo C520WS v2 cameras. By sending crafted files to the firmware update endpoint, an unauthenticated attacker can disrupt core system services before authentication or firmware integrity is verified. This exploitation leads to a persistent denial-of-service condition, requiring a manual reboot or an application-initiated restart to restore normal functionality.
Exploitation of this vulnerability causes a persistent denial-of-service condition, disrupting core system services and requiring a manual reboot or application-initiated restart to restore normal operation.
Users are advised to update to the latest firmware version. The updated firmware for the Tapo C220 v1 is available on the TP-Link website. For the Tapo C520WS v2, the latest firmware can also be downloaded from the TP-Link website.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.