CVE-2026-12760
Description
A denial-of-service (DoS) vulnerability has been identified in Tapo C200 v3 in the network packet handling logic due to improper handling of IPv4 fragmented packets. An unauthenticated adjacent attacker can send crafted packets to cause excessive resource consumption, leading to instability of the device.Successful exploitation can remotely trigger a temporary denial-of-service condition, causing the camera to become unresponsive and resulting in intermittent loss of video monitoring and recording.
Summary dbcve.org
The Tapo C200 v3 camera has a denial-of-service vulnerability in its network packet handling logic. The device improperly handles IPv4 fragmented packets, allowing an unauthenticated adjacent attacker to send crafted packets that cause excessive resource consumption, leading to device instability and unresponsiveness.
Mitigation
Apply the vendor-provided firmware update for the Tapo C200 v3 when available. Until then, network segmentation and firewall rules can limit the attack surface from adjacent network attackers.