---
id: CVE-2026-104944
title: |-
  TP-Link Tapo
  C500 v2.0 contains an out-of-bounds function-pointer dispatch in its TDP
  (TP-Link Device Protocol) daemon
summary: |-
  TP-Link Tapo
  C500 v2.0 contains an out-of-bounds function-pointer dispatch in its TDP
  (TP-Link Device Protocol) daemon. A single unauthenticated UDP datagram can
  cause an invalid indirect call, crashing the main service and resulting in …
severity: high
cvss: 7.1
cvssVector: 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'
cwe:
  - CWE-823
vendor: TP-Link Systems Inc.
product: Tapo C500 v2.0
affected:
  - tapo_c500_v2.0 < 1.3.5 Build 260810
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T20:03:53.457'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-104944'
references:
  - url: >-
      https://www.tp-link.com/en/support/download/tapo-c500/#Firmware-Release-Notes
    label: f23511db-6c3e-4e32-a477-6aa17d310630
  - url: >-
      https://www.tp-link.com/us/support/download/tapo-c500/#Firmware-Release-Notes
    label: f23511db-6c3e-4e32-a477-6aa17d310630
  - url: 'https://www.tp-link.com/us/support/faq/5327/'
    label: f23511db-6c3e-4e32-a477-6aa17d310630
tags:
  - nvd
  - cve.org
cvssSource: cna
ingestedAt: '2026-10-06T19:13:33.938Z'
---

## Overview

TP-Link Tapo
C500 v2.0 contains an out-of-bounds function-pointer dispatch in its TDP
(TP-Link Device Protocol) daemon. A single unauthenticated UDP datagram can
cause an invalid indirect call, crashing the main service and resulting in a
denial-of-service condition.





Successful
exploitation may allow an unauthenticated attacker with network access to the
affected UDP service to repeatedly crash the TDP daemon, disrupting normal
device operation and availability. No authentication, session establishment, or
pairing is required to trigger the condition.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
