{"id":"CVE-2026-75618","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-75618","summary":"Tapo C100/C101 V5 contains a null pointer dereference vulnerability in the RTSP service. An attacker on the local network can send specially crafted requests that cause the service…","details":"Tapo C100/C101 V5 contains a null pointer dereference vulnerability in the RTSP service. An attacker on the local network can send specially crafted requests that cause the service to dereference an invalid pointer, resulting in a service crash and device reboot. Successful exploitation can disrupt live video streaming functionality and cause a temporary denial-of-service condition.","published":"2026-08-19T19:17:24.630","modified":"2026-08-19T19:17:24.630","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://www.tp-link.com/en/support/download/tapo-c100/#Firmware-Release-Notes"},{"type":"WEB","url":"https://www.tp-link.com/us/support/download/tapo-c100/#Firmware-Release-Notes"},{"type":"WEB","url":"https://www.tp-link.com/us/support/download/tapo-c101/#Firmware-Release-Notes"},{"type":"WEB","url":"https://www.tp-link.com/us/support/faq/5251/"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-08-19T19:17:24.630"}}