{"id":"CVE-2026-15316","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-15316","summary":"An improper input\nvalidation vulnerability in the configuration service for processing encrypted\ncredential data has been identified in Tapo C200 v5.  An attacker can send oversized…","details":"An improper input\nvalidation vulnerability in the configuration service for processing encrypted\ncredential data has been identified in Tapo C200 v5.  An attacker can send oversized crypted\nciphertext values that may trigger exception handling failures, due to insufficient\nvalidation, causing the affected device to crash or restart.\n\n\n\n\n\nSuccessful\nexploitation may temporarily disrupt HTTPS management and monitoring\nfunctionality, resulting in a denial-of-service (DoS) condition until the\nservice recovers.","published":"2026-08-18T22:16:49.367","modified":"2026-08-18T22:16:49.367","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://www.tp-link.com/en/support/download/tapo-c200/v5/"},{"type":"WEB","url":"https://www.tp-link.com/us/support/download/tapo-c200/v5/"},{"type":"WEB","url":"https://www.tp-link.com/us/support/faq/5248/"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-08-18T22:16:49.367"}}