PT-2026-29848 · Tp Link Systems+1 · Tapo C520Ws V2.6+1

Published

2026-04-02

·

Updated

2026-04-29

·

CVE-2026-34120

CVSS v4.0

7.1

High

VectorAV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions TP-Link Tapo C520WS version 2.6
Description A heap-based buffer overflow occurs during the asynchronous parsing of local video stream content and the handling of HTTP POST request bodies. This issue stems from insufficient alignment and validation of buffer boundaries when processing streaming inputs and improper boundary checks during memory allocation or copying in the HTTP server component. An attacker on the same network segment can trigger heap memory corruption by sending crafted payloads, leading to a Denial-of-Service (DoS) condition where the device process crashes or becomes unresponsive. Depending on the architectural context, this could also lead to information disclosure or remote code execution.
Recommendations Update the device to a version that addresses this issue once the vendor update becomes available. Implement network segmentation to limit exposure of management interfaces. Monitor device logs for unusual or malformed HTTP POST requests.

Fix

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-34120

Affected Products

Tapo C520Ws V2.6
Tapo C520Ws Firmware