Tapo C120 v1 and C200 v5
contain a NULL pointer dereference in the HTTPS onboarding connect request parser. The interface is reachable without
authentication after initial setup and does not validate that a password field
is present for certain authentication and encryption parameter combinations,
allowing a malformed request from the same local network to crash the HTTPS service
Successful exploitation may
temporarily make HTTPS management functions unavailable. Repeated malformed
requests may sustain the denial-of-service condition, and recovery may in some
cases require a device reboot.
contain a NULL pointer dereference in the HTTPS onboarding connect request parser. The interface is reachable without
authentication after initial setup and does not validate that a password field
is present for certain authentication and encryption parameter combinations,
allowing a malformed request from the same local network to crash the HTTPS service
Successful exploitation may
temporarily make HTTPS management functions unavailable. Repeated malformed
requests may sustain the denial-of-service condition, and recovery may in some
cases require a device reboot.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 01 Oct 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Tapo C120 v1 and C200 v5 contain a NULL pointer dereference in the HTTPS onboarding connect request parser. The interface is reachable without authentication after initial setup and does not validate that a password field is present for certain authentication and encryption parameter combinations, allowing a malformed request from the same local network to crash the HTTPS service Successful exploitation may temporarily make HTTPS management functions unavailable. Repeated malformed requests may sustain the denial-of-service condition, and recovery may in some cases require a device reboot. | |
| Title | Unauthenticated Onboarding Connect NULL Pointer Dereference Denial of Service Vulnerability in TP-Link Tapo C120 & C200 | |
| Weaknesses | CWE-476 | |
| References |
|
|
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: TPLink
Published:
Updated: 2026-10-01T17:41:31.004Z
Reserved: 2026-05-19T16:30:36.090Z
Link: CVE-2026-9032
No data.
Status : Received
Published: 2026-10-01T18:17:29.390
Modified: 2026-10-01T18:17:29.390
Link: CVE-2026-9032
No data.
OpenCVE Enrichment
No data.
Weaknesses