CVE-2026-1315Disclosure(tp-link / tapo_c220)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

By sending crafted files to the firmware update endpoint of Tapo C220 v1 and C520WS v2, the device terminates core system services before verifying authentication or firmware integrity. An unauthenticated attacker can trigger a persistent denial of service, requiring a manual reboot or application initiated restart to restore normal device operation.

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-20

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • tapo_c220
  • tapo_c220_firmware
  • tapo_c520ws
  • tapo_c520ws_firmware

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-01-27); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
tapo_c220tapo_c220_firmwaretapo_c520wstapo_c520ws_firmware

2 versions affected across 4 products

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-01-27: 2Mentions · 2026-03-12: 1Technical Details · 2026-01-27: 2Technical Details · 2026-03-12: 101-2703-12
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-01-272
Disclosure2
2026-03-121
Disclosure1
Full discourse3 posts
  • DailyCVE@dailycve
    Disclosure

    🔴 Tapo Cameras #CVE-2026-1315 - Improper Input Validation leads to Persistent DoS (High) https://dailycve.com/tapo-cameras-cve-2026-1315-improper-input-validation-leads-to-persistent-dos-high/

    Post summary

    The post announces CVE-2026-1315 for Tapo Cameras, describing an improper input validation that causes a persistent DoS with high severity, while providing no PoC, exploit, patch, or evidence of active exploitation.

    0000035
    167 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-1315 Tapo C220 and C520WS Firmware Update Endpoint Denial of Service Vulnerability https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-1315

    Post summary

    The text announces CVE-2026-1315, a denial-of-service flaw in the firmware update endpoint of Tapo C220 and C520WS, providing minimal technical details and no exploitation or mitigation information.

    0000055
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-1315 By sending crafted files to the firmware update endpoint of Tapo C220 v1 and C520WS v2, the device terminates core system services before verifying authentication or fi… https://www.cve.org/CVERecord?id=CVE-2026-1315

    Post summary

    CVE‑2026‑1315 discloses that crafted files sent to the firmware update endpoint of Tapo C220 v1 and C520WS v2 can cause a denial of service by terminating core services before authentication, highlighting a critical flaw in the device's update handling.

    00000202
    56.5K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
HWtp-linktapo_c2201--
OStp-linktapo_c220_firmware---
HWtp-linktapo_c520ws2--
OStp-linktapo_c520ws_firmware---

Explore more