{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2026-15316",
        "assignerOrgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
        "state": "PUBLISHED",
        "assignerShortName": "TPLink",
        "dateReserved": "2026-07-09T17:55:11.713Z",
        "datePublished": "2026-08-18T21:25:11.118Z",
        "dateUpdated": "2026-08-20T15:36:48.337Z"
    },
    "containers": {
        "cna": {
            "providerMetadata": {
                "orgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
                "shortName": "TPLink",
                "dateUpdated": "2026-08-18T21:25:11.118Z"
            },
            "title": "Denial-of-Service via Oversized Encrypted Credential Input in TP-Link Tapo C200",
            "problemTypes": [
                {
                    "descriptions": [
                        {
                            "lang": "en",
                            "cweId": "CWE-20",
                            "description": "CWE-20 Improper input validation",
                            "type": "CWE"
                        }
                    ]
                }
            ],
            "impacts": [
                {
                    "capecId": "CAPEC-24",
                    "descriptions": [
                        {
                            "lang": "en",
                            "value": "CAPEC-24 Filter Failure through Buffer Overflow"
                        }
                    ]
                }
            ],
            "affected": [
                {
                    "vendor": "TP-Link Systems Inc.",
                    "product": "Tapo C200 v5",
                    "versions": [
                        {
                            "status": "affected",
                            "version": "0",
                            "lessThan": "V5_1.4.6 Build 260709 Rel.27675n",
                            "versionType": "custom"
                        }
                    ],
                    "defaultStatus": "unaffected"
                }
            ],
            "descriptions": [
                {
                    "lang": "en",
                    "value": "An improper input\nvalidation vulnerability in the configuration service for processing encrypted\ncredential data has been identified in Tapo C200 v5.  An attacker can send oversized crypted\nciphertext values that may trigger exception handling failures, due to insufficient\nvalidation, causing the affected device to crash or restart.\n\n\n\n\n\nSuccessful\nexploitation may temporarily disrupt HTTPS management and monitoring\nfunctionality, resulting in a denial-of-service (DoS) condition until the\nservice recovers.",
                    "supportingMedia": [
                        {
                            "type": "text/html",
                            "base64": false,
                            "value": "<p><span>An improper input\nvalidation vulnerability in the configuration service for processing encrypted\ncredential data has been identified in Tapo C200 v5.</span><span>&nbsp; </span><span>An attacker can send oversized crypted\nciphertext values that may trigger exception handling failures, due to insufficient\nvalidation, causing the affected device to crash or restart.</span></p>\n\n<p>Successful\nexploitation may temporarily disrupt HTTPS management and monitoring\nfunctionality, resulting in a denial-of-service (DoS) condition until the\nservice recovers.</p>"
                        }
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://www.tp-link.com/us/support/download/tapo-c200/v5/",
                    "tags": [
                        "patch"
                    ]
                },
                {
                    "url": "https://www.tp-link.com/en/support/download/tapo-c200/v5/",
                    "tags": [
                        "patch"
                    ]
                },
                {
                    "url": "https://www.tp-link.com/us/support/faq/5248/",
                    "tags": [
                        "vendor-advisory"
                    ]
                }
            ],
            "metrics": [
                {
                    "format": "CVSS",
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "GENERAL"
                        }
                    ],
                    "cvssV4_0": {
                        "attackVector": "ADJACENT",
                        "attackComplexity": "LOW",
                        "attackRequirements": "NONE",
                        "privilegesRequired": "NONE",
                        "userInteraction": "NONE",
                        "vulnConfidentialityImpact": "NONE",
                        "subConfidentialityImpact": "NONE",
                        "vulnIntegrityImpact": "NONE",
                        "subIntegrityImpact": "NONE",
                        "vulnAvailabilityImpact": "HIGH",
                        "subAvailabilityImpact": "NONE",
                        "exploitMaturity": "NOT_DEFINED",
                        "Safety": "NOT_DEFINED",
                        "Automatable": "NOT_DEFINED",
                        "Recovery": "NOT_DEFINED",
                        "valueDensity": "NOT_DEFINED",
                        "vulnerabilityResponseEffort": "NOT_DEFINED",
                        "providerUrgency": "NOT_DEFINED",
                        "version": "4.0",
                        "baseSeverity": "HIGH",
                        "baseScore": 7.1,
                        "vectorString": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"
                    }
                }
            ],
            "credits": [
                {
                    "lang": "en",
                    "value": "Thai Do (Lio) and Khoi Tran (KayTii) from OPSWAT",
                    "type": "finder"
                }
            ],
            "source": {
                "discovery": "UNKNOWN"
            },
            "x_generator": {
                "engine": "Vulnogram 1.0.4"
            }
        },
        "adp": [
            {
                "metrics": [
                    {
                        "other": {
                            "type": "ssvc",
                            "content": {
                                "id": "CVE-2026-15316",
                                "role": "CISA Coordinator",
                                "options": [
                                    {
                                        "Exploitation": "none"
                                    },
                                    {
                                        "Automatable": "no"
                                    },
                                    {
                                        "Technical Impact": "partial"
                                    }
                                ],
                                "version": "2.0.3",
                                "timestamp": "2026-08-20T13:31:45.040163Z"
                            }
                        }
                    }
                ],
                "title": "CISA ADP Vulnrichment",
                "providerMetadata": {
                    "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
                    "shortName": "CISA-ADP",
                    "dateUpdated": "2026-08-20T15:36:48.337Z"
                }
            }
        ]
    }
}