CVE-2026-34119Disclosure(tp-link / tapo_c520ws)

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch tp-link tapo_c520ws systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A heap-based buffer overflow vulnerability was identified in TP-Link Tapo C520WS v2.6 within the HTTP parsing loop when appending segmented request bodies without continuous write‑boundary verification, due to insufficient boundary validation when handling externally supplied HTTP input.  An attacker on the same network segment could trigger heap memory corruption conditions by sending crafted payloads that cause write operations beyond allocated buffer boundaries.  Successful exploitation causes a Denial-of-Service (DoS) condition, causing the device’s process to crash or become unresponsive.

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-122

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • tapo_c520ws
  • tapo_c520ws_firmware

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 3 mentions (2026-04-03); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
tapo_c520wstapo_c520ws_firmware

1 version affected across 2 products

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-04-03: 3Mentions · 2026-04-10: 1Patch / Workaround · 2026-04-03: 3Technical Details · 2026-04-03: 3Technical Details · 2026-04-10: 104-0304-10
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-04-033
Disclosure2Patch1
2026-04-101
Disclosure1
Full discourse4 posts
  • iototsecnews@iototsecnews
    Disclosure

    TP-Link Tapo C520WS に複数の深刻な脆弱性:DoS 攻撃とシステム・クラッシュの恐れ https://iototsecnews.jp/2026/04/03/multiple-tp-link-vulnerabilities-let-attackers-trigger-dos-and-crash-routers/ これらの脆弱性の主な原因は、ネットワークからのリクエストを受け取る際の、処理の不備にあります。特に CVE-2026-34121 では、JSON リクエストを解析する際の認証ロジックに問題があり、必要な手順がバイパスされてしまう状況にあります。また、CVE-2026-34118/CVE-2026-34119/CVE-2026-34120/CVE-2026-34122/CVE-2026-34124 では、データの長さやパスの変換を正しく計算/検証できていないために、バッファ・オーバーフローによるメモリ破壊とカメラの停止が引き起こされます。ご利用のチームは、ご注意ください。 #CVE202634118 #CVE202634119 #CVE202634120 #CVE202634121 #CVE202634122 #CVE202634124 #TapoC520WS #TPLink #Vulnerability

    Post summary

    The article announces several serious vulnerabilities (CVE‑2026‑34118 through CVE‑2026‑34124) in TP‑Link Tapo C520WS that can trigger DoS or system crashes due to authentication bypass and buffer overflow issues.

    01000175
    483 followersView on X
  • Syed Aquib@syedaquib77
    Patch

    ⚠️ **Vulnerability Alert:** Multiple vulnerabilities in TP-Link Tapo C520WS cameras (DoS and authentication bypass) 📅 **Timeline:** Disclosure: 2026-04-02; Patch available (see vendor release notes) 🆔 **CVE-2026-34121** | 📊 CVSS: 8.7 (HIGH 🟠) | 📈 EPSS: Not Available% 🆔 **CVE-2026-34118** | 📊 CVSS: 7.1 (HIGH 🟠) | 📈 EPSS: Not Available% 🆔 **CVE-2026-34119** | 📊 CVSS: 7.1 (HIGH 🟠) | 📈 EPSS: Not Available% 🆔 **CVE-2026-34120** | 📊 CVSS: 7.1 (HIGH 🟠) | 📈 EPSS: Not Available% 🆔 **CVE-2026-34122** | 📊 CVSS: 7.1 (HIGH 🟠) | 📈 EPSS: Not Available% 🆔 **CVE-2026-34124** | 📊 CVSS: 7.1 (HIGH 🟠) | 📈 EPSS: Not Available% 🛠️ **Exploit Maturity:** Not Available 📂 **Affected Versions:** Tapo C520WS v2.6 (firmware before 1.2.4 Build 260326 Rel. 24666n) 🔧 **Fixed Versions:** 1.2.4 Build 260326 Rel. 24666n 🫨 **Attack Vectors:** - Adjacent network (same local network segment) 📝 **Summary:** Multiple high‑severity flaws allow unauthenticated attackers on the local network to crash Tapo C520WS devices (DoS) and bypass authentication to modify settings or access functionality, creating outages and privacy risks. Immediate firmware updates and network controls are required to prevent device unavailability and unauthorized configuration changes. 📈 **Impact Scope:** Devices may crash or reboot, lose streaming/monitoring capability, or have configuration/state modified by unauthenticated actors — causing blind spots and privacy exposure. 🛡️ **Recommended Actions:** - Apply TP-Link firmware update to 1.2.4 Build 260326 Rel. 24666n (or later) immediately. - Segment cameras onto a separate VLAN and restrict inter-segment access. - Disable remote administration and unnecessary services; rotate local/admin credentials. - Monitor device logs for crashes, unexpected reboots, or config changes; apply network controls (ARP inspection, MAC filtering). 🪢 **Related Resources:** - https://www.tp-link.com/en/support/download/tapo-c520ws/#Firmware-Release-Notes - https://nvd.nist.gov/vuln/detail/CVE-2026-34121 🏷 **Tags:** #Cybersecurity #IoT #TPLink

    Post summary

    The alert details multiple high‑severity DoS and authentication bypass flaws in TP‑Link Tapo C520WS cameras and recommends immediately applying the vendor firmware update and implementing network controls.

    0001060
    277 followersView on X
  • Syed Aquib@syedaquib77
    Disclosure

    ⚠️ **Vulnerability Alert:** Multiple Buffer Overflow and Auth Bypass Vulnerabilities in TP-Link Tapo C520WS (CVE-2026-34118 through CVE-2026-34124) 📅 **Timeline:** Disclosure: 2026-04-02; Patch: Not stated 🆔 **CVE-2026-34118** | 📊 CVSS: 7.1 (HIGH 🟠) 🆔 **CVE-2026-34119** | 📊 CVSS: 7.1 (HIGH 🟠) 🆔 **CVE-2026-34120** | 📊 CVSS: 7.1 (HIGH 🟠) 🆔 **CVE-2026-34121** | 📊 CVSS: 8.7 (HIGH 🟠) 🆔 **CVE-2026-34122** | 📊 CVSS: 7.1 (HIGH 🟠) 🆔 **CVE-2026-34123** 🆔 **CVE-2026-34124** | 📊 CVSS: 7.1 (HIGH 🟠) 🛠️ **Exploit Maturity:** Not Available 🔧 **Fixed Versions:** Patched by TP-Link (vendor firmware update; specific fixed version not stated) 🫨 **Attack Vectors:** - Adjacent network (same network segment) — crafted HTTP requests - Unauthenticated HTTP request / authorization bypass (CVE-2026-34121) - Streaming/local video request parsing vectors 📝 **Summary:** Multiple heap- and stack-based buffer overflows in Tapo C520WS allow adjacent-network attackers to trigger crashes/DoS and potentially escalate to remote code execution depending on exploitability. Separately, CVE-2026-34121 is an unauthenticated authorization bypass that permits unauthorized configuration changes. 📈 **Impact Scope:** Widely deployed Tapo C520WS devices in homes and businesses — risks include device outages, unauthorized configuration changes, privacy exposure, and potential lateral compromise if memory-corruption flaws are weaponized. 🛡️ **Recommended Actions:** - Apply the TP-Link firmware update immediately when available and verify device versions - Isolate cameras on a dedicated VLAN and restrict HTTP/management access - Block or limit HTTP access from untrusted networks and the internet - Monitor device logs and network traffic for abnormal HTTP requests and repeated crashes - Maintain an inventory of affected devices and consider temporary removal from sensitive networks if you cannot patch 🪢 **Related Resources:** - https://www.tp-link.com/en/support/download/tapo-c520ws/#Firmware-Release-Notes - https://cyberpress.org/critical-tp-link/ 🏷 **Tags:** #Cybersecurity #IoT #TapoC520WS

    Post summary

    TP‑Link Tapo C520WS is exposed to a series of high‑CVSS buffer‑overflow and authentication‑bypass flaws (CVE‑2026‑34118‑34124). No active exploitation or PoC is reported; firmware updates and network hardening are recommended.

    0000066
    277 followersView on X
  • Syed Aquib@syedaquib77
    Disclosure

    ⚠️ **Vulnerability Alert:** TP-Link Tapo C520WS — multiple adjacent-network vulnerabilities (DoS, crash, authentication bypass) 📅 **Timeline:** Disclosure: 2026-04-02; Patch: firmware available (see fixed versions) 🆔 **CVE-2026-34121** | 📊 CVSS: 8.7 (HIGH 🟠) | 📈 EPSS: Not Available% 🆔 **CVE-2026-34118** | 📊 CVSS: 7.1 (HIGH 🟠) | 📈 EPSS: Not Available% 🆔 **CVE-2026-34119** | 📊 CVSS: 7.1 (HIGH 🟠) | 📈 EPSS: Not Available% 🆔 **CVE-2026-34120** | 📊 CVSS: 7.1 (HIGH 🟠) | 📈 EPSS: Not Available% 🆔 **CVE-2026-34122** | 📊 CVSS: 7.1 (HIGH 🟠) | 📈 EPSS: Not Available% 🆔 **CVE-2026-34124** | 📊 CVSS: 7.1 (HIGH 🟠) | 📈 EPSS: Not Available% 🛠️ **Exploit Maturity:** Not Available 📂 **Affected Versions:** TP-Link Tapo C520WS v2.6 (firmware before 1.2.4 Build 260326 Rel.24666n) 🔧 **Fixed Versions:** 1.2.4 Build 260326 Rel.24666n 🫨 **Attack Vectors:** - Adjacent network (local/Wi‑Fi) - HTTP DS configuration service (authentication bypass) - Malformed HTTP POST / segmented requests (heap overflows) - Asynchronous video stream input (heap overflow) - HTTP request path normalization (path-expansion overflow) 📝 **Summary:** Unauthenticated attackers on the same network can crash or reboot Tapo C520WS devices (multiple heap/stack overflows) and CVE-2026-34121 enables an authentication bypass that permits unauthorized configuration changes and potential access to device functions/streams. These flaws create immediate physical security and privacy risks for camera deployments. 📈 **Impact Scope:** Unauthenticated local attackers can cause Denial-of-Service (device crash/reboot) and, via auth bypass, make privileged configuration changes or access device functionality, creating security blind spots. 🛡️ **Recommended Actions:** - Immediately update devices to firmware 1.2.4 Build 260326 Rel.24666n (verify installed version) - Segment cameras on a VLAN and restrict Wi‑Fi access; disable unnecessary remote management/port-forwarding - Monitor device availability and logs for crashes or unexpected config changes; reinstall firmware if integrity is suspect - Contact TP-Link support and follow vendor guidance 🪢 **Related Resources:** - https://www.youtube.com/watch?v=KsZ6tROaVOQ - https://en.wikipedia.org/wiki/2 🏷 **Tags:** #Cybersecurity #TPLink #TapoC520WS

    Post summary

    The post announces multiple adjacent‑network flaws in TP‑Link Tapo C520WS firmware, including authentication bypass and heap overflows, and lists the patched firmware version, but does not provide evidence of exploitation or PoC.

    0000096
    277 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWtp-linktapo_c520ws2.6--
OStp-linktapo_c520ws_firmware---

Explore more