Junglewise Threat Intelligence

CVE-2026-34118: TP-Link Tapo C520WS heap overflow in HTTP POST parsing

CVE-2026-34118 · Severity: medium · CVSS 6.5 · Published 2026-04-02

Technologies: TP-Link Tapo C520WS, TP-Link Tapo C520ws Firmware. Vendors: TP-Link.

Executive brief

A security vulnerability has been identified in the TP-Link Tapo C520WS, a popular outdoor security camera. An attacker on the same local network can send a specially crafted web request to the device to cause it to crash or become unresponsive. This results in a denial-of-service, effectively disabling the camera's security monitoring and recording capabilities.

Technical details

A heap-based buffer overflow (CWE-122) exists in the TP-Link Tapo C520WS v2.6 within the HTTP POST body parsing logic. The vulnerability is caused by insufficient boundary validation and a failure to verify remaining buffer capacity after dynamic allocation when handling externally supplied HTTP input. An attacker located on the same network segment can exploit this by sending crafted payloads that trigger write operations beyond the allocated buffer boundaries. Successful exploitation results in heap memory corruption, leading to a process crash or device unresponsiveness (Denial-of-Service). The issue is addressed in firmware versions 1.2.4 Build 260326 Rel.24666n and later.

Affected products

  • TP-Link Tapo C520WS v2.6 up to (excluding) 1.2.4 Build 260326 Rel.24666n

Timeline

  • 2026-04-02: advisory: Initial advisory published by TP-Link and NVD
  • 2026-04-02: disclosed

References

Related threats