PT-2026-29848 · Tp Link Systems+1 · Tapo C520Ws V2.6+1
Published
2026-04-02
·
Updated
2026-04-29
·
CVE-2026-34120
CVSS v4.0
7.1
High
| Vector | AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
TP-Link Tapo C520WS version 2.6
Description
A heap-based buffer overflow occurs during the asynchronous parsing of local video stream content and the handling of HTTP POST request bodies. This issue stems from insufficient alignment and validation of buffer boundaries when processing streaming inputs and improper boundary checks during memory allocation or copying in the HTTP server component. An attacker on the same network segment can trigger heap memory corruption by sending crafted payloads, leading to a Denial-of-Service (DoS) condition where the device process crashes or becomes unresponsive. Depending on the architectural context, this could also lead to information disclosure or remote code execution.
Recommendations
Update the device to a version that addresses this issue once the vendor update becomes available.
Implement network segmentation to limit exposure of management interfaces.
Monitor device logs for unusual or malformed HTTP POST requests.
Fix
Heap Based Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tapo C520Ws V2.6
Tapo C520Ws Firmware