CVE-2026-104945Medium· 6.8▾ SunlitTP-Link Tapo C500 v2.0 contains an out-of-bounds stack write vulnerability in its ONVIF PTZ SOAP handlers. An authenticated ONVIF client can submit an excessive number of preset-related elements, causing writes beyond the bounds of fixed…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 37.4 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
TP-Link Tapo C500 v2.0 contains an out-of-bounds stack write vulnerability in its ONVIF PTZ SOAP handlers. An authenticated ONVIF client can submit an excessive number of preset-related elements, causing writes beyond the bounds of fixed-size stack arrays and resulting in a crash of the affected service.
Successful exploitation may allow an authenticated attacker to cause the affected service to crash, resulting in a denial-of-service condition. Repeated exploitation may repeatedly disrupt camera management and PTZ-related functionality until the service recovers or restarts.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-104944High· 7.1TP-Link Tapo C500 v2.0 contains an out-of-bounds function-pointer dispatch in its TDP (TP-Link Device Protocol) daemon
CVE-2026-8618High· 7.7A stack-based buffer overflow vulnerability exists in the TDDPv2 service (/usr/bin/tddp) on Deco M9 Plus due to insufficient validation of decrypted request data length before it is copied into a fixed-size stack buffer in the subtype 0x…
CVE-2026-85384High· 8.5A stack-based buffer overflow vulnerability exists in the httpd component of RE210 AC750 due to improper bounds checking in the splitString function when processing an uploaded configuration file
CVE-2026-102370Medium· 5.4Kasa EC70 v4 and EC71 v4 do not logically disable the production debug interface at the firmware or chip level and do not lock the bootloader. Although the debug traces are physically severed during manufacturing, an attacker with physi…
CVE-2026-84682High· 7.7A command injection vulnerability exists in the TDDPv2 service (/usr/bin/tddp) on Archer AX90 V1
CVE-2026-9032High· 7.1Tapo C120 v1 and C200 v5 contain a NULL pointer dereference in the HTTPS onboarding connect request parser. The interface is reachable without authentication after initial setup and does not validate that a password field is present for…