SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-15316

MEDIUM · CVSS 6.5 EPSS 0.23% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-18 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The vulnerability affects the Tapo C200 v5 configuration service, which improperly validates input for encrypted credential data. An attacker can exploit this flaw by sending oversized encrypted ciphertext, leading to exception handling failures that may crash or restart the device, causing a denial-of-service (DoS) condition. Organizations using this device should prioritize remediation to maintain service availability and security.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-15316
Severity
MEDIUM
CVSS
6.5
EPSS
0.23%

Original NVD Description

An improper input validation vulnerability in the configuration service for processing encrypted credential data has been identified in Tapo C200 v5.  An attacker can send oversized crypted ciphertext values that may trigger exception handling failures, due to insufficient validation, causing the affected device to crash or restart. Successful exploitation may temporarily disrupt HTTPS management and monitoring functionality, resulting in a denial-of-service (DoS) condition until the service recovers.

Related CVEs

Other vulnerabilities affecting the same vendor(s)