Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g9c2-p6j5-8cv4

Опубликовано: 27 янв. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 7.1

Описание

By sending crafted files to the firmware update endpoint of Tapo C220 v1 and C520WS v2, the device terminates core system services before verifying authentication or firmware integrity. An unauthenticated attacker can trigger a persistent denial of service, requiring a manual reboot or application initiated restart to restore normal device operation.

By sending crafted files to the firmware update endpoint of Tapo C220 v1 and C520WS v2, the device terminates core system services before verifying authentication or firmware integrity. An unauthenticated attacker can trigger a persistent denial of service, requiring a manual reboot or application initiated restart to restore normal device operation.

EPSS

Процентиль: 16%
0.00053
Низкий

7.1 High

CVSS4

Дефекты

CWE-20

Связанные уязвимости

nvd
11 дней назад

By sending crafted files to the firmware update endpoint of Tapo C220 v1 and C520WS v2, the device terminates core system services before verifying authentication or firmware integrity. An unauthenticated attacker can trigger a persistent denial of service, requiring a manual reboot or application initiated restart to restore normal device operation.

EPSS

Процентиль: 16%
0.00053
Низкий

7.1 High

CVSS4

Дефекты

CWE-20