CVE-2026-104944High· 7.1▾ TwilightTP-Link Tapo C500 v2.0 contains an out-of-bounds function-pointer dispatch in its TDP (TP-Link Device Protocol) daemon. A single unauthenticated UDP datagram can cause an invalid indirect call, crashing the main service and resulting in …
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 39.1 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
TP-Link Tapo C500 v2.0 contains an out-of-bounds function-pointer dispatch in its TDP (TP-Link Device Protocol) daemon. A single unauthenticated UDP datagram can cause an invalid indirect call, crashing the main service and resulting in a denial-of-service condition.
Successful exploitation may allow an unauthenticated attacker with network access to the affected UDP service to repeatedly crash the TDP daemon, disrupting normal device operation and availability. No authentication, session establishment, or pairing is required to trigger the condition.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-104945Medium· 6.8TP-Link Tapo C500 v2.0 contains an out-of-bounds stack write vulnerability in its ONVIF PTZ SOAP handlers
CVE-2026-102370Medium· 5.4Kasa EC70 v4 and EC71 v4 do not logically disable the production debug interface at the firmware or chip level and do not lock the bootloader. Although the debug traces are physically severed during manufacturing, an attacker with physi…
CVE-2026-84682High· 7.7A command injection vulnerability exists in the TDDPv2 service (/usr/bin/tddp) on Archer AX90 V1
CVE-2026-8618High· 7.7A stack-based buffer overflow vulnerability exists in the TDDPv2 service (/usr/bin/tddp) on Deco M9 Plus due to insufficient validation of decrypted request data length before it is copied into a fixed-size stack buffer in the subtype 0x…
CVE-2026-9032High· 7.1Tapo C120 v1 and C200 v5 contain a NULL pointer dereference in the HTTPS onboarding connect request parser. The interface is reachable without authentication after initial setup and does not validate that a password field is present for…
CVE-2026-78578High· 7.1Tapo C120 v1 and C200 v5 do not enforce authentication for do method HTTPS onboarding connect actions after initial setup. An unauthenticated adjacent attacker can submit unauthorized wireless configuration parameters, causing the camer…