CVE-2026-34118Disclosure(tp-link / tapo_c520ws)

LOWCVSS 6.5 · MEDIUM

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Patch tp-link tapo_c520ws systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A heap-based buffer overflow vulnerability was identified in TP-Link Tapo C100/C101 v5, C520WS v2.6 in the HTTP POST body parsing logic due to missing validation of remaining buffer capacity after dynamic allocation, due to insufficient boundary validation when handling externally supplied HTTP input.   An attacker on the same network segment could trigger heap memory corruption conditions by sending crafted payloads that cause write operations beyond allocated buffer boundaries.  Successful exploitation causes a Denial-of-Service (DoS) condition, causing the device’s process to crash or become unresponsive.

2.0/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-122

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • tapo_c520ws
  • tapo_c520ws_firmware

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 7 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 7 signals
  • Disclosure: 5 classified signals
  • Peaked 2d ago at 4 mentions (2026-04-03); latest day: 2
  • 7 total mentions across 3 days

Affected systems

Vendors
Products
tapo_c520wstapo_c520ws_firmware

1 version affected across 2 products

Deep dive

Activity timeline7 mentions / 3d
01234Mentions · 2026-04-03: 4Mentions · 2026-04-10: 1Mentions · 2026-04-30: 2PoC Mentioned / Linked · 2026-04-30: 2Patch / Workaround · 2026-04-03: 4Technical Details · 2026-04-03: 4Technical Details · 2026-04-10: 1Technical Details · 2026-04-30: 204-0304-1004-30
Signal classification2 categories
Disclosure
571.4%
Patch
228.6%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-04-034
Disclosure2Patch2
2026-04-101
Disclosure1
2026-04-302
Disclosure2
Full discourse7 posts
  • yousukezan@yousukezan
    Disclosure

    TP-Linkの屋外防犯カメラTapo C520WS v2.6に高深刻度の脆弱性群が判明した。認証回避やクラッシュを招く恐れがあり、同一ネットワーク上の攻撃者により監視が無効化される可能性がある。 対象はCVE-2026-34118~CVE-2026-34124で、最大CVSS v4.0は8.7に達する。中でもCVE-2026-34121は設定サービスの認証処理におけるJSON解析と権限判定の不整合に起因し、未認証のまま特権操作に便乗させることで制限された設定変更を実行できる。これによりデバイス状態の改ざんが可能となる。加えて、外部入力の境界検証不足によるヒープオーバーフロー(CVE-2026-34118~34120)、過長パラメータで発生するスタックオーバーフロー(CVE-2026-34122)、正規化時のパス展開を考慮しない長さ制限不備(CVE-2026-34124)も確認され、いずれもプロセス停止を引き起こし得る。影響はファームウェア1.2.4 Build 260326 Rel.24666n未満に及ぶ。対策として最新版への更新、IoT機器のネットワーク分離、ログと設定の定期監査が推奨される。 https://securityonline.info/tp-link-tapo-c520ws-security-vulnerabilities-firmware-patch/

    Post summary

    TP‑Link Tapo C520WS firmware contains high‑severity vulnerabilities (CVE‑2026‑34118 to CVE‑2026‑34124) that could enable authentication bypass, crashes, and unauthorized configuration changes; firmware updates and network isolation are recommended to mitigate the risks.

    051952.2K
    14.3K followersView on X
  • Nicolas Krassas@Dinosn
    Disclosure

    CVE-2026-34118: TP-Link HTTP POST body heap buffer overflow https://labs.taszk.io/blog/post/115_tp_heap_bof/

    Post summary

    A new heap buffer overflow vulnerability (CVE‑2026‑34118) affecting TP‑Link devices has been disclosed, with a linked blog post that likely includes detailed information and a proof‑of‑concept.

    030221.1K
    158.1K followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    TP-Link Tapo C520WS に複数の深刻な脆弱性:DoS 攻撃とシステム・クラッシュの恐れ https://iototsecnews.jp/2026/04/03/multiple-tp-link-vulnerabilities-let-attackers-trigger-dos-and-crash-routers/ これらの脆弱性の主な原因は、ネットワークからのリクエストを受け取る際の、処理の不備にあります。特に CVE-2026-34121 では、JSON リクエストを解析する際の認証ロジックに問題があり、必要な手順がバイパスされてしまう状況にあります。また、CVE-2026-34118/CVE-2026-34119/CVE-2026-34120/CVE-2026-34122/CVE-2026-34124 では、データの長さやパスの変換を正しく計算/検証できていないために、バッファ・オーバーフローによるメモリ破壊とカメラの停止が引き起こされます。ご利用のチームは、ご注意ください。 #CVE202634118 #CVE202634119 #CVE202634120 #CVE202634121 #CVE202634122 #CVE202634124 #TapoC520WS #TPLink #Vulnerability

    Post summary

    The article discloses multiple serious vulnerabilities in the TP‑Link Tapo C520WS, detailing an authentication bypass and several buffer overflows that can cause DoS and device crashes, but it does not provide proof‑of‑concepts, exploit code, or patch information.

    01000175
    483 followersView on X
  • Syed Aquib@syedaquib77
    Patch

    ⚠️ **Vulnerability Alert:** Multiple vulnerabilities in TP-Link Tapo C520WS cameras (DoS and authentication bypass) 📅 **Timeline:** Disclosure: 2026-04-02; Patch available (see vendor release notes) 🆔 **CVE-2026-34121** | 📊 CVSS: 8.7 (HIGH 🟠) | 📈 EPSS: Not Available% 🆔 **CVE-2026-34118** | 📊 CVSS: 7.1 (HIGH 🟠) | 📈 EPSS: Not Available% 🆔 **CVE-2026-34119** | 📊 CVSS: 7.1 (HIGH 🟠) | 📈 EPSS: Not Available% 🆔 **CVE-2026-34120** | 📊 CVSS: 7.1 (HIGH 🟠) | 📈 EPSS: Not Available% 🆔 **CVE-2026-34122** | 📊 CVSS: 7.1 (HIGH 🟠) | 📈 EPSS: Not Available% 🆔 **CVE-2026-34124** | 📊 CVSS: 7.1 (HIGH 🟠) | 📈 EPSS: Not Available% 🛠️ **Exploit Maturity:** Not Available 📂 **Affected Versions:** Tapo C520WS v2.6 (firmware before 1.2.4 Build 260326 Rel. 24666n) 🔧 **Fixed Versions:** 1.2.4 Build 260326 Rel. 24666n 🫨 **Attack Vectors:** - Adjacent network (same local network segment) 📝 **Summary:** Multiple high‑severity flaws allow unauthenticated attackers on the local network to crash Tapo C520WS devices (DoS) and bypass authentication to modify settings or access functionality, creating outages and privacy risks. Immediate firmware updates and network controls are required to prevent device unavailability and unauthorized configuration changes. 📈 **Impact Scope:** Devices may crash or reboot, lose streaming/monitoring capability, or have configuration/state modified by unauthenticated actors — causing blind spots and privacy exposure. 🛡️ **Recommended Actions:** - Apply TP-Link firmware update to 1.2.4 Build 260326 Rel. 24666n (or later) immediately. - Segment cameras onto a separate VLAN and restrict inter-segment access. - Disable remote administration and unnecessary services; rotate local/admin credentials. - Monitor device logs for crashes, unexpected reboots, or config changes; apply network controls (ARP inspection, MAC filtering). 🪢 **Related Resources:** - https://www.tp-link.com/en/support/download/tapo-c520ws/#Firmware-Release-Notes - https://nvd.nist.gov/vuln/detail/CVE-2026-34121 🏷 **Tags:** #Cybersecurity #IoT #TPLink

    Post summary

    High‑severity vulnerabilities in TP‑Link Tapo C520WS allow unauthenticated local attackers to cause DoS and bypass authentication; a firmware patch to 1.2.4 is available and immediate updates plus network segregation are advised.

    0001060
    277 followersView on X
  • ✪ 𝕱𝖆𝖍𝖆𝖉@fad_777
    Disclosure

    ثغرة CVE-2026-34118: مشكلة تجاوز سعة الذاكرة المؤقتة في HTTP POST بجهاز TP-Link. للمزيد: https://labs.taszk.io/blog/post/115_tp_heap_bof/ CVE-2026-34118: TP-Link devices are vulnerable to an HTTP POST body heap buffer overflow. More details: https://labs.taszk.io/blog/post/115_tp_heap_bof/ #CyberSecurity #Vulnerability #TPLINK #TechNews

    Post summary

    The text announces CVE‑2026‑34118 affecting TP‑Link devices, describing a heap buffer overflow in HTTP POST bodies and directing readers to a blog for further details.

    0000055
    62 followersView on X
  • Syed Aquib@syedaquib77
    Disclosure

    ⚠️ **Vulnerability Alert:** Multiple Buffer Overflow and Auth Bypass Vulnerabilities in TP-Link Tapo C520WS (CVE-2026-34118 through CVE-2026-34124) 📅 **Timeline:** Disclosure: 2026-04-02; Patch: Not stated 🆔 **CVE-2026-34118** | 📊 CVSS: 7.1 (HIGH 🟠) 🆔 **CVE-2026-34119** | 📊 CVSS: 7.1 (HIGH 🟠) 🆔 **CVE-2026-34120** | 📊 CVSS: 7.1 (HIGH 🟠) 🆔 **CVE-2026-34121** | 📊 CVSS: 8.7 (HIGH 🟠) 🆔 **CVE-2026-34122** | 📊 CVSS: 7.1 (HIGH 🟠) 🆔 **CVE-2026-34123** 🆔 **CVE-2026-34124** | 📊 CVSS: 7.1 (HIGH 🟠) 🛠️ **Exploit Maturity:** Not Available 🔧 **Fixed Versions:** Patched by TP-Link (vendor firmware update; specific fixed version not stated) 🫨 **Attack Vectors:** - Adjacent network (same network segment) — crafted HTTP requests - Unauthenticated HTTP request / authorization bypass (CVE-2026-34121) - Streaming/local video request parsing vectors 📝 **Summary:** Multiple heap- and stack-based buffer overflows in Tapo C520WS allow adjacent-network attackers to trigger crashes/DoS and potentially escalate to remote code execution depending on exploitability. Separately, CVE-2026-34121 is an unauthenticated authorization bypass that permits unauthorized configuration changes. 📈 **Impact Scope:** Widely deployed Tapo C520WS devices in homes and businesses — risks include device outages, unauthorized configuration changes, privacy exposure, and potential lateral compromise if memory-corruption flaws are weaponized. 🛡️ **Recommended Actions:** - Apply the TP-Link firmware update immediately when available and verify device versions - Isolate cameras on a dedicated VLAN and restrict HTTP/management access - Block or limit HTTP access from untrusted networks and the internet - Monitor device logs and network traffic for abnormal HTTP requests and repeated crashes - Maintain an inventory of affected devices and consider temporary removal from sensitive networks if you cannot patch 🪢 **Related Resources:** - https://www.tp-link.com/en/support/download/tapo-c520ws/#Firmware-Release-Notes - https://cyberpress.org/critical-tp-link/ 🏷 **Tags:** #Cybersecurity #IoT #TapoC520WS

    Post summary

    This post announces multiple high‑severity buffer overflow and authentication bypass vulnerabilities in the TP‑Link Tapo C520WS, provides technical details, and advises applying vendor firmware updates and mitigating measures.

    0000066
    277 followersView on X
  • Syed Aquib@syedaquib77
    Patch

    ⚠️ **Vulnerability Alert:** TP-Link Tapo C520WS — multiple adjacent-network vulnerabilities (DoS, crash, authentication bypass) 📅 **Timeline:** Disclosure: 2026-04-02; Patch: firmware available (see fixed versions) 🆔 **CVE-2026-34121** | 📊 CVSS: 8.7 (HIGH 🟠) | 📈 EPSS: Not Available% 🆔 **CVE-2026-34118** | 📊 CVSS: 7.1 (HIGH 🟠) | 📈 EPSS: Not Available% 🆔 **CVE-2026-34119** | 📊 CVSS: 7.1 (HIGH 🟠) | 📈 EPSS: Not Available% 🆔 **CVE-2026-34120** | 📊 CVSS: 7.1 (HIGH 🟠) | 📈 EPSS: Not Available% 🆔 **CVE-2026-34122** | 📊 CVSS: 7.1 (HIGH 🟠) | 📈 EPSS: Not Available% 🆔 **CVE-2026-34124** | 📊 CVSS: 7.1 (HIGH 🟠) | 📈 EPSS: Not Available% 🛠️ **Exploit Maturity:** Not Available 📂 **Affected Versions:** TP-Link Tapo C520WS v2.6 (firmware before 1.2.4 Build 260326 Rel.24666n) 🔧 **Fixed Versions:** 1.2.4 Build 260326 Rel.24666n 🫨 **Attack Vectors:** - Adjacent network (local/Wi‑Fi) - HTTP DS configuration service (authentication bypass) - Malformed HTTP POST / segmented requests (heap overflows) - Asynchronous video stream input (heap overflow) - HTTP request path normalization (path-expansion overflow) 📝 **Summary:** Unauthenticated attackers on the same network can crash or reboot Tapo C520WS devices (multiple heap/stack overflows) and CVE-2026-34121 enables an authentication bypass that permits unauthorized configuration changes and potential access to device functions/streams. These flaws create immediate physical security and privacy risks for camera deployments. 📈 **Impact Scope:** Unauthenticated local attackers can cause Denial-of-Service (device crash/reboot) and, via auth bypass, make privileged configuration changes or access device functionality, creating security blind spots. 🛡️ **Recommended Actions:** - Immediately update devices to firmware 1.2.4 Build 260326 Rel.24666n (verify installed version) - Segment cameras on a VLAN and restrict Wi‑Fi access; disable unnecessary remote management/port-forwarding - Monitor device availability and logs for crashes or unexpected config changes; reinstall firmware if integrity is suspect - Contact TP-Link support and follow vendor guidance 🪢 **Related Resources:** - https://www.youtube.com/watch?v=KsZ6tROaVOQ - https://en.wikipedia.org/wiki/2 🏷 **Tags:** #Cybersecurity #TPLink #TapoC520WS

    Post summary

    The post announces disclosure of several high‑severity CVEs affecting TP‑Link Tapo C520WS cameras, details technical attack vectors, and emphatically recommends applying the available firmware patch to mitigate the risks.

    0000096
    277 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWtp-linktapo_c520ws2.6--
OStp-linktapo_c520ws_firmware---

Explore more