MEDIUMVulnerability

CVE-2026-75619

Tapo C100/C101 V5 contains a heap-based buffer overflow vulnerability in the RTSP service. An authenticated attacker on the local network can send specially crafted RTSP frame data containing oversized length values, resulting in out-of-bounds heap writes. Successful exploitation can crash the RTSP service and trigger a device reboot, resulting in a temporary denial-of-service condition.

Properties

severity
MEDIUM
score
5.7
epss_score
0.00217
cve_id
CVE-2026-75619
vector
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
published_at
2026-08-19T19:17:24.760
last_modified
2026-09-04T17:08:32.987
epss_percentile
0.12035

Related Entities (7)

ENRICHED_BY (1)

[Source]FIRST EPSS

AFFECTS_PRODUCT (4)

[Product]
[Product]
[Product]
[Product]

DESCRIBED_BY (1)

[Source]NVD

HAS_WEAKNESS (1)

[Weakness]Heap-based Buffer Overflow

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-75619 — Ninja Signal Threat Intelligence | Ninja Signal