Metrics
Affected Vendors & Products
Wed, 11 Mar 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tp-link tapo C220
Tp-link tapo C220 Firmware Tp-link tapo C520ws Tp-link tapo C520ws Firmware |
|
| CPEs | cpe:2.3:h:tp-link:tapo_c220:1:*:*:*:*:*:*:* cpe:2.3:h:tp-link:tapo_c520ws:2:*:*:*:*:*:*:* cpe:2.3:o:tp-link:tapo_c220_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:tp-link:tapo_c520ws_firmware:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Tp-link tapo C220
Tp-link tapo C220 Firmware Tp-link tapo C520ws Tp-link tapo C520ws Firmware |
|
| Metrics |
cvssV3_1
|
Tue, 10 Feb 2026 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 28 Jan 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tp-link
Tp-link tapo Tp-link tapo C220 V1 Tp-link tapo C520ws V2 |
|
| Vendors & Products |
Tp-link
Tp-link tapo Tp-link tapo C220 V1 Tp-link tapo C520ws V2 |
Tue, 27 Jan 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 27 Jan 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Tapo C220 v1 and C520WS v2 cameras’ HTTP service does not safely handle POST requests containing an excessively large Content-Length header. The resulting failed memory allocation triggers a NULL pointer dereference, causing the main service process to crash. An unauthenticated attacker can repeatedly crash the service, causing temporary denial of service. The device restarts automatically, and repeated requests can keep it unavailable. | |
| Title | Null Pointer Dereference in Tapo SmartCam HTTP Service on TP-Link Tapo C220 & C520WS | |
| Weaknesses | CWE-476 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: TPLink
Published:
Updated: 2026-02-09T23:45:04.943Z
Reserved: 2026-01-13T19:43:58.914Z
Link: CVE-2026-0918
Updated: 2026-01-27T18:07:21.888Z
Status : Analyzed
Published: 2026-01-27T18:15:54.973
Modified: 2026-03-11T22:26:15.683
Link: CVE-2026-0918
No data.
OpenCVE Enrichment
Updated: 2026-01-28T12:21:51Z