Security Advisory

CVE-2026-1871

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-06-02 16:13:36
Last updated 2026-06-02 18:24:54
Assigner TPLink
CVSS score not scored
State PUBLISHED

Description

TP-Link Tapo C200 v5 contains a stack-based buffer overflow flaw in RTSP authentication handling due to improper validation of Authorization header field lengths, which can be triggered by a crafted authentication request. Successful exploitation causes the affected RTSP core service process to crash and triggers an automatic system reboot, resulting in a denial of service (DoS) condition. This prevents legitimate users from accessing the camera’s live video stream or management interface until the service restarts.