CVE-2026-12760

EUVD-2026-39026
A denial-of-service (DoS) vulnerability has been identified in Tapo C200 v3 in the network packet handling logic due to improper handling of IPv4 fragmented packets.  An unauthenticated adjacent attacker can send crafted packets to cause excessive resource consumption, leading to instability of the device.Successful exploitation can remotely trigger a temporary denial-of-service condition, causing the camera to become unresponsive and resulting in intermittent loss of video monitoring and recording.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.5 MEDIUM
ADJACENT_NETWORK
LOW
NONE
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 12.83%
Affected Products (NVD)
VendorProductVersion
tp-linktapo_c200_firmware
1.3.3:build_230228
tp-linktapo_c200_firmware
1.3.4:build_230424
tp-linktapo_c200_firmware
1.3.5:build_230717
tp-linktapo_c200_firmware
1.3.7:build_230920
tp-linktapo_c200_firmware
1.3.9:build_231019
tp-linktapo_c200_firmware
1.3.11:build_231115
tp-linktapo_c200_firmware
1.3.13:build_240327
tp-linktapo_c200_firmware
1.3.14:build_240513
tp-linktapo_c200_firmware
1.3.15:build_240715
tp-linktapo_c200_firmware
1.4.1:build_241212
tp-linktapo_c200_firmware
1.4.2:build_250313
𝑥
= Vulnerable software versions