MEDIUM 6.5

CVE-2026-12760: TP-Link Tapo C200 v3 IPv4 Fragmentation DoS Vulnerability

The Tapo C200 v3 camera contains a flaw in how it processes fragmented network traffic that allows an attacker on the same local network to disable the device temporarily. By sending specially crafted packets, an attacker can consume excessive resources on the camera, causing it to stop responding and interrupting video monitoring and recording. No authentication or user interaction is required—the attacker simply needs network adjacency to the device.

Source data · NVD / CISA · public domain

CVSS
3.1 · 6.5 MEDIUM · CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weaknesses (CWE)
CWE-770
Affected products
12 configuration(s)
Published / Modified
2026-06-24 / 2026-06-29

NVD description (verbatim)

A denial-of-service (DoS) vulnerability has been identified in Tapo C200 v3 in the network packet handling logic due to improper handling of IPv4 fragmented packets.  An unauthenticated adjacent attacker can send crafted packets to cause excessive resource consumption, leading to instability of the device.Successful exploitation can remotely trigger a temporary denial-of-service condition, causing the camera to become unresponsive and resulting in intermittent loss of video monitoring and recording.

3 reference(s) · View on NVD →

SEC.co analysis · AI-assisted, reviewed against source

Technical summary

CVE-2026-12760 is a denial-of-service vulnerability in TP-Link Tapo C200 v3 stemming from improper handling of IPv4 fragmented packets (CWE-770: Allocation of Resources Without Limits or Throttling). The vulnerability resides in the network packet handling logic. When an unauthenticated attacker sends crafted fragmented packets to an adjacent network location, the device fails to properly throttle or validate resource consumption during reassembly, leading to memory exhaustion or CPU overload. This causes the camera to become unresponsive, resulting in temporary loss of availability. The CVSS 3.1 score of 6.5 (MEDIUM) reflects the attack vector requiring network adjacency and no authentication, but no confidentiality or integrity impact—only availability is degraded.

Business impact

Organizations relying on Tapo C200 v3 cameras for continuous surveillance or security monitoring face intermittent outages of video feeds without warning or direct user action. An attacker with local network access can disrupt monitoring capabilities at will, potentially creating blind spots during critical periods. For deployments in sensitive environments, this availability loss poses operational and security risks. The temporary nature of the DoS means repeated attacks could create a pattern of unreliability, undermining confidence in the monitoring infrastructure.

Affected systems

TP-Link Tapo C200 v3 firmware is confirmed affected. The vulnerability advisory should be consulted to determine if other Tapo C200 firmware versions or related Tapo models share the same flaw, as the source data lists the product multiple times. Organizations should verify their exact firmware version and device variant against TP-Link's official advisory to confirm exposure.

Exploitability

Exploitation requires the attacker to be on the same local network as the device (adjacent network access) and does not require authentication or user interaction. Crafting the malicious fragmented packets requires minimal technical skill once the attack principle is understood. The ease of triggering the DoS and the accessibility of the attack surface make this practical for an adversary within network range. However, the attacker cannot achieve code execution, data theft, or persistence—only temporary disruption.

Remediation

TP-Link has released or is releasing a firmware patch addressing the improper handling of IPv4 fragmented packets. Organizations should verify the patch version and availability from TP-Link's official support channels. In parallel, network segmentation and access controls can limit which hosts can reach the camera, reducing the pool of potential attackers. For high-availability deployments, implementing camera redundancy and network monitoring to detect anomalous packet patterns can help mitigate the availability impact.

Patch guidance

Consult TP-Link's official advisory for the corrected firmware version applicable to your Tapo C200 v3 device. Verify the firmware build number before and after patching to ensure successful application. If automatic update is available through the Tapo app or device settings, enable it; otherwise, manual firmware upload may be required. Test the patched device under normal operating conditions to confirm stability. Prioritize patching for cameras deployed in critical monitoring locations or sensitive networks.

Detection guidance

Monitor for alerts from intrusion detection systems (IDS) or network monitoring tools that flag unusual fragmented IPv4 traffic directed at camera IP addresses. Watch for sudden, unexplained unavailability of specific camera feeds, particularly if availability recovers after a short period without intervention. Correlate such events with network traffic logs to identify sources of fragmented packets. Log camera uptime and responsiveness metrics to establish baselines and detect patterns of intermittent outages that may indicate exploitation attempts.

Why prioritize this

Although the CVSS score is MEDIUM (6.5), prioritization should account for the device's role in your environment. Cameras deployed in secure facilities, perimeter monitoring, or compliance-critical areas warrant higher urgency. The low barrier to exploitation (adjacent network access, no authentication) and the lack of active user action required mean that any adversary with network reach can trigger the DoS. Organizations with flat network architectures or guest Wi-Fi networks bridged to IoT devices face elevated risk.

Risk score, explained

The CVSS 3.1 score of 6.5 reflects a MEDIUM severity: the attack vector is adjacent (AV:A), not remote; the attack complexity is low (AC:L); no privileges or user interaction are required (PR:N, UI:N); and the impact is scoped to the device itself (S:U) with availability completely compromised (A:H) but no confidentiality or integrity loss. The score appropriately penalizes the attack requirement for network adjacency while recognizing that availability loss in a security camera is a notable operational concern.

Frequently asked questions

Can this vulnerability be exploited from the internet, or only from the local network?

Only from the local network. The attack requires network adjacency (the attacker must be on the same layer 2 or adjacent layer 3 network as the camera). This means an attacker cannot exploit it remotely over the internet unless they have already compromised an internal host or have direct access to the network segment where the camera resides.

Does exploitation allow an attacker to view stored video or change camera settings?

No. This vulnerability only causes a denial-of-service condition, making the camera temporarily unresponsive. It does not enable data theft, viewing of video feeds, credential harvesting, or modification of device settings. Once the malicious traffic stops, the camera typically recovers without user intervention.

What should I do if I cannot patch immediately?

Implement network segmentation to restrict which hosts can communicate with the camera. Use firewall rules or VLAN isolation to limit access to authorized monitoring systems only. Enable network monitoring to detect unusual IPv4 fragmented traffic. Monitor camera uptime and set alerts for unexpected outages. For high-priority deployments, consider deploying a second camera on a separate network segment to maintain redundancy during potential attacks or patching windows.

Is this vulnerability being actively exploited?

As of the vulnerability publication date, this flaw has not been added to the CISA KEV catalog, indicating no confirmed evidence of active, widespread exploitation. However, the low barrier to exploitation means organizations should not rely on lack of current exploitation as justification for delaying remediation.

This analysis is provided for informational purposes to support vulnerability management and risk assessment. SEC.co makes no warranties regarding the accuracy or completeness of this content and disclaims liability for direct or indirect losses resulting from reliance upon it. Verify all patch versions, affected product lists, and remediation steps against the official TP-Link advisory before implementing changes. CVSS scores and attack vector classifications are derived from published CVE data and should be adapted to your organization's specific network architecture and threat model. Organizations remain responsible for assessing their own exposure and determining appropriate remediation timelines. Source: NVD (public-domain), retrieved 2026-08-02. Analysis generated by SEC.co (claude-haiku-4-5).