PT-2026-29847 · Tp Link Systems+1 · Tapo C520Ws V2.6+1
Published
2026-04-02
·
Updated
2026-04-29
·
CVE-2026-34119
CVSS v4.0
7.1
High
| Vector | AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
TP-Link Tapo C520WS version 2.6
Description
A heap-based buffer overflow exists in the HTTP parsing loop when appending segmented request bodies. This occurs due to insufficient boundary validation when handling externally supplied HTTP input, specifically within the HTTP POST body parsing mechanism. An attacker on the same network segment can trigger heap memory corruption by sending crafted payloads that cause write operations beyond allocated buffer boundaries, resulting in a Denial-of-Service (DoS) condition where the device process crashes or becomes unresponsive.
Recommendations
Update TP-Link Tapo C520WS version 2.6 to the latest firmware version provided by the vendor.
Fix
Heap Based Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tapo C520Ws V2.6
Tapo C520Ws Firmware