CVE-2026-0918 | TP-Link Tapo C220 v1/Tapo C520WS v2 HTTP Service null pointer dereference
A vulnerability marked as problematic has been reported in TP-Link Tapo C220 v1 and Tapo C520WS v2. This affects an unknown part of the component HTTP Service. This manipulation causes null pointer dereference.
This vulnerability is handled as CVE-2026-0918. The attack can only be done within the local network. There is not any exploit available.