Answer in brief
CVE-2026-104945 records a Medium severity (CVSS 6.8) vulnerability in Authenticated ONVIF PTZ Out-of-Bounds Stack Write Denial of Service in TP-Link Tapo C500. The current sources do not mark it as known exploited. The current feed maps TP-Link Systems Inc./Tapo C500 v2.0 (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 6.8. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps TP-Link Systems Inc./Tapo C500 v2.0 (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| TP-Link Systems Inc./Tapo C500 v2.0generic | >=0 <1.3.5 Build 260810 | 1.3.5 Build 260810, 1.3.5 |
Published upstream
Oct 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Oct 6, 2026
TP-Link Tapo C500 v2.0 contains an out-of-bounds stack write vulnerability in its ONVIF PTZ SOAP handlers. An authenticated ONVIF client can submit an excessive number of preset-related elements, causing writes beyond the bounds of fixed-size stack arrays and resulting in a crash of the affected service. Successful exploitation may allow an authenticated attacker to cause the affected service to crash, resulting in a denial-of-service condition. Repeated exploitation may repeatedly disrupt camera management and PTZ-related functionality until the service recovers or restarts.
Quoted source text, attributed separately from HOL analysis.