{"id":"CVE-2026-104945","title":"TP-Link Tapo\nC500 v2.0 contains an out-of-bounds stack write vulnerability in its ONVIF PTZ\nSOAP handlers","summary":"TP-Link Tapo\nC500 v2.0 contains an out-of-bounds stack write vulnerability in its ONVIF PTZ\nSOAP handlers. An authenticated ONVIF client can submit an excessive number of\npreset-related elements, causing writes beyond the bounds of fixed…","severity":"medium","cvss":6.8,"cvssVector":"CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","cwe":["CWE-121"],"vendor":"TP-Link Systems Inc.","product":"Tapo C500 v2.0","affected":["tapo_c500_v2.0 < 1.3.5 Build 260810"],"published":"2026-10-06","updated":"2026-10-06","sourceUpdated":"2026-10-06T20:03:53.457","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-104945","references":[{"url":"https://www.tp-link.com/en/support/download/tapo-c500/#Firmware-Release-Notes","label":"f23511db-6c3e-4e32-a477-6aa17d310630"},{"url":"https://www.tp-link.com/us/support/download/tapo-c500/#Firmware-Release-Notes","label":"f23511db-6c3e-4e32-a477-6aa17d310630"},{"url":"https://www.tp-link.com/us/support/faq/5327/","label":"f23511db-6c3e-4e32-a477-6aa17d310630"}],"tags":["nvd","cve.org"],"cvssSource":"cna","ingestedAt":"2026-10-06T19:13:33.924Z","slug":"CVE-2026-104945","body":"## Overview\n\nTP-Link Tapo\nC500 v2.0 contains an out-of-bounds stack write vulnerability in its ONVIF PTZ\nSOAP handlers. An authenticated ONVIF client can submit an excessive number of\npreset-related elements, causing writes beyond the bounds of fixed-size stack\narrays and resulting in a crash of the affected service.\n\n\n\n\n\n\n\n\n\nSuccessful\nexploitation may allow an authenticated attacker to cause the affected service\nto crash, resulting in a denial-of-service condition. Repeated exploitation may\nrepeatedly disrupt camera management and PTZ-related functionality until the\nservice recovers or restarts.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":37,"depthScoreParts":{"impact":37.4,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}