{"id":"CVE-2026-104944","title":"TP-Link Tapo\nC500 v2.0 contains an out-of-bounds function-pointer dispatch in its TDP\n(TP-Link Device Protocol) daemon","summary":"TP-Link Tapo\nC500 v2.0 contains an out-of-bounds function-pointer dispatch in its TDP\n(TP-Link Device Protocol) daemon. A single unauthenticated UDP datagram can\ncause an invalid indirect call, crashing the main service and resulting in …","severity":"high","cvss":7.1,"cvssVector":"CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","cwe":["CWE-823"],"vendor":"TP-Link Systems Inc.","product":"Tapo C500 v2.0","affected":["tapo_c500_v2.0 < 1.3.5 Build 260810"],"published":"2026-10-06","updated":"2026-10-06","sourceUpdated":"2026-10-06T20:03:53.457","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-104944","references":[{"url":"https://www.tp-link.com/en/support/download/tapo-c500/#Firmware-Release-Notes","label":"f23511db-6c3e-4e32-a477-6aa17d310630"},{"url":"https://www.tp-link.com/us/support/download/tapo-c500/#Firmware-Release-Notes","label":"f23511db-6c3e-4e32-a477-6aa17d310630"},{"url":"https://www.tp-link.com/us/support/faq/5327/","label":"f23511db-6c3e-4e32-a477-6aa17d310630"}],"tags":["nvd","cve.org"],"cvssSource":"cna","ingestedAt":"2026-10-06T19:13:33.938Z","slug":"CVE-2026-104944","body":"## Overview\n\nTP-Link Tapo\nC500 v2.0 contains an out-of-bounds function-pointer dispatch in its TDP\n(TP-Link Device Protocol) daemon. A single unauthenticated UDP datagram can\ncause an invalid indirect call, crashing the main service and resulting in a\ndenial-of-service condition.\n\n\n\n\n\nSuccessful\nexploitation may allow an unauthenticated attacker with network access to the\naffected UDP service to repeatedly crash the TDP daemon, disrupting normal\ndevice operation and availability. No authentication, session establishment, or\npairing is required to trigger the condition.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":39,"depthScoreParts":{"impact":39.1,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}