MEDIUM

CVE-2026-12760

Tp-link Tapo C200 Firmware 2026-06-24 CVSS v3.1
CVSS
6.5

Description

A denial-of-service (DoS) vulnerability has been identified in Tapo C200 v3 in the network packet handling logic due to improper handling of IPv4 fragmented packets.  An unauthenticated adjacent attacker can send crafted packets to cause excessive resource consumption, leading to instability of the device.Successful exploitation can remotely trigger a temporary denial-of-service condition, causing the camera to become unresponsive and resulting in intermittent loss of video monitoring and recording.

Summary dbcve.org

The Tapo C200 v3 camera has a denial-of-service vulnerability in its network packet handling logic. The device improperly handles IPv4 fragmented packets, allowing an unauthenticated adjacent attacker to send crafted packets that cause excessive resource consumption, leading to device instability and unresponsiveness.

Mitigation

Apply the vendor-provided firmware update for the Tapo C200 v3 when available. Until then, network segmentation and firewall rules can limit the attack surface from adjacent network attackers.

Weakness (CWE)

CWE-770 Resource Allocation Without Limits

EPSS Score

0.36%
Probability of exploitation in next 30 days
29.8th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE