Vulnerability Description
A denial-of-service (DoS) vulnerability has been identified in Tapo C200 v3 in the network packet handling logic due to improper handling of IPv4 fragmented packets. An unauthenticated adjacent attacker can send crafted packets to cause excessive resource consumption, leading to instability of the device.Successful exploitation can remotely trigger a temporary denial-of-service condition, causing the camera to become unresponsive and resulting in intermittent loss of video monitoring and recording.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Tp-Link | Tapo C200 Firmware | 1.3.3 |
| Tp-Link | Tapo C200 | 3 |
Related Weaknesses (CWE)
References
- https://www.tp-link.com/en/support/download/tapo-c200/v3/#Firmware-Release-NotesRelease Notes
- https://www.tp-link.com/us/support/download/tapo-c200/v3/#Firmware-Release-NotesRelease Notes
- https://www.tp-link.com/us/support/faq/5143/Vendor Advisory
FAQ
What is CVE-2026-12760?
CVE-2026-12760 is a vulnerability with a CVSS score of 6.5 (MEDIUM). A denial-of-service (DoS) vulnerability has been identified in Tapo C200 v3 in the network packet handling logic due to improper handling of IPv4 fragmented packets. An unauthenticated adjacent attac...
How severe is CVE-2026-12760?
CVE-2026-12760 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-12760?
Check the references section above for vendor advisories and patch information. Affected products include: Tp-Link Tapo C200 Firmware, Tp-Link Tapo C200.