SEPTEMBER 11, 2026
Live Feed
Back to database
Case File

CVE-2026-75618

MEDIUM · CVSS 6.5 EPSS 0.23% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-19 · Last synced 2026-09-11

CyberRota Analysis

AI-Generated

The Tapo C100/C101 V5 devices are vulnerable due to a null pointer dereference in their RTSP service, allowing local attackers to send crafted requests that lead to service crashes and device reboots. This vulnerability can disrupt live video streaming and create a temporary denial-of-service condition. Users and administrators of affected devices should prioritize remediation to maintain service availability and security.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-75618
Severity
MEDIUM
CVSS
6.5
EPSS
0.23%

Original NVD Description

Tapo C100/C101 V5 contains a null pointer dereference vulnerability in the RTSP service. An attacker on the local network can send specially crafted requests that cause the service to dereference an invalid pointer, resulting in a service crash and device reboot. Successful exploitation can disrupt live video streaming functionality and cause a temporary denial-of-service condition.

Related CVEs

Other vulnerabilities affecting the same vendor(s)