CVE-2026-0918Disclosure(tp-link / tapo_c220)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Tapo C100 v5, C220 v1 and C520WS v2 cameras’ HTTP service does not safely handle POST requests containing an excessively large Content-Length header. The resulting failed memory allocation triggers a NULL pointer dereference, causing the main service process to crash. An unauthenticated attacker can repeatedly crash the service, causing temporary denial of service. The device restarts automatically, and repeated requests can keep it unavailable.

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-476

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • tapo_c220
  • tapo_c220_firmware
  • tapo_c520ws
  • tapo_c520ws_firmware

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-01-27); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
tapo_c220tapo_c220_firmwaretapo_c520wstapo_c520ws_firmware

2 versions affected across 4 products

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-01-27: 2Mentions · 2026-03-12: 1Technical Details · 2026-01-27: 201-2703-12
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-01-272
Disclosure1General1
2026-03-121
Disclosure1
Full discourse3 posts
  • DailyCVE@dailycve
    Disclosure

    🔴 Tapo C220 & C520WS, Denial of Service, #CVE-2026-0918 (High) https://dailycve.com/tapo-c220-c520ws-denial-of-service-cve-2026-0918-high/

    Post summary

    A headline reports a high‑severity denial‑of‑service vulnerability, CVE-2026-0918, affecting Tapo C220 and C520WS devices.

    0000028
    167 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-0918 Denial of Service in TP-Link Tapo C220 and C520WS Cameras via HTTP Header Overflow https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-0918

    Post summary

    The post announces a Denial of Service vulnerability (CVE-2026-0918) in TP‑Link Tapo cameras caused by an HTTP header overflow, with no evidence of exploitation or patches available.

    0000065
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-0918 The Tapo C220 v1 and C520WS v2 cameras’ HTTP service does not safely handle POST requests containing an excessively large Content-Length header. The resulting failed me… https://www.cve.org/CVERecord?id=CVE-2026-0918

    Post summary

    CVE-2026-0918 details how Tapo C220 and C520WS cameras' HTTP service fails when receiving a POST request with an overly large Content-Length header.

    00000241
    56.5K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
HWtp-linktapo_c2201--
OStp-linktapo_c220_firmware---
HWtp-linktapo_c520ws2--
OStp-linktapo_c520ws_firmware---

Explore more