CVE-2026-12760
Denial-of-Service Vulnerability via Malformed IPv4 Fragmentation Handling in TP-Link Tapo C200
Description
A denial-of-service (DoS) vulnerability has been identified in Tapo C200 v3 in the network packet handling logic due to improper handling of IPv4 fragmented packets. An unauthenticated adjacent attacker can send crafted packets to cause excessive resource consumption, leading to instability of the device.Successful exploitation can remotely trigger a temporary denial-of-service condition, causing the camera to become unresponsive and resulting in intermittent loss of video monitoring and recording.
INFO
Published Date :
June 24, 2026, 6:10 p.m.
Last Modified :
June 24, 2026, 6:10 p.m.
Remotely Exploit :
No
Source :
TPLink
CVSS Scores
| Score | Version | Severity | Vector | Exploitability Score | Impact Score | Source |
|---|---|---|---|---|---|---|
| CVSS 4.0 | HIGH | f23511db-6c3e-4e32-a477-6aa17d310630 |
Solution
- Update device firmware to the latest version.
- Apply security patches when available.
- Restrict network access to the device.
- Monitor device for unusual network activity.
We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).
Results are limited to the first 15 repositories due to potential performance issues.
The following list is the news that have been mention
CVE-2026-12760 vulnerability anywhere in the article.