PT-2026-29847 · Tp Link Systems+1 · Tapo C520Ws V2.6+1

Published

2026-04-02

·

Updated

2026-04-29

·

CVE-2026-34119

CVSS v4.0

7.1

High

VectorAV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions TP-Link Tapo C520WS version 2.6
Description A heap-based buffer overflow exists in the HTTP parsing loop when appending segmented request bodies. This occurs due to insufficient boundary validation when handling externally supplied HTTP input, specifically within the HTTP POST body parsing mechanism. An attacker on the same network segment can trigger heap memory corruption by sending crafted payloads that cause write operations beyond allocated buffer boundaries, resulting in a Denial-of-Service (DoS) condition where the device process crashes or becomes unresponsive.
Recommendations Update TP-Link Tapo C520WS version 2.6 to the latest firmware version provided by the vendor.

Fix

Heap Based Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2026-34119

Affected Products

Tapo C520Ws V2.6
Tapo C520Ws Firmware