Answer in brief
CVE-2026-104944 records a High severity (CVSS 7.1) vulnerability in Unauthenticated TDP Function Pointer Dispatch Denial of Service in TP-Link Tapo C500. The current sources do not mark it as known exploited. The current feed maps TP-Link Systems Inc./Tapo C500 v2.0 (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 7.1. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps TP-Link Systems Inc./Tapo C500 v2.0 (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| TP-Link Systems Inc./Tapo C500 v2.0generic | >=0 <1.3.5 Build 260810 | 1.3.5 Build 260810, 1.3.5 |
Published upstream
Oct 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Oct 6, 2026
TP-Link Tapo C500 v2.0 contains an out-of-bounds function-pointer dispatch in its TDP (TP-Link Device Protocol) daemon. A single unauthenticated UDP datagram can cause an invalid indirect call, crashing the main service and resulting in a denial-of-service condition. Successful exploitation may allow an unauthenticated attacker with network access to the affected UDP service to repeatedly crash the TDP daemon, disrupting normal device operation and availability. No authentication, session establishment, or pairing is required to trigger the condition.
Quoted source text, attributed separately from HOL analysis.