PT-2026-29851 · Tp Link Systems+1 · Tapo C520Ws V2.6+1

Published

2026-04-02

·

Updated

2026-04-29

·

CVE-2026-34124

CVSS v4.0

7.1

High

VectorAV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions TP-Link Tapo C520WS version 2.6
Description A stack buffer overflow exists in the HTTP server due to improper HTTP request path parsing logic. While length restrictions are enforced on the raw request path, the system fails to account for path expansion during normalization. An attacker on the adjacent network can send crafted HTTP GET or POST requests to cause memory corruption and buffer overflow, resulting in process termination, system interruption, or device reboot, leading to a denial-of-service (DoS) condition.
Recommendations Update the firmware of TP-Link Tapo C520WS version 2.6 to the latest official release. Implement robust input validation at network perimeters to filter malformed HTTP traffic.

Fix

Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2026-34124

Affected Products

Tapo C520Ws V2.6
Tapo C520Ws Firmware