Executive brief
A security vulnerability has been identified in the TP-Link Tapo C520WS, a smart outdoor security camera. An attacker on the same local network could send specially crafted data to the device to cause it to crash or become unresponsive. This results in a denial-of-service, preventing the camera from recording video or providing security monitoring until it is recovered.
Technical details
A heap-based buffer overflow (CWE-122) exists in the TP-Link Tapo C520WS v2.6 within the HTTP parsing loop. The vulnerability is triggered when the device appends segmented request bodies without continuous write-boundary verification. An attacker located on the same network segment can exploit this by sending crafted HTTP payloads that exceed allocated buffer boundaries, leading to heap memory corruption. Successful exploitation results in the device process crashing or becoming unresponsive (Denial of Service). The issue is addressed in firmware version 1.2.4 Build 260326 Rel.24666n and later.
Affected products
- TP-Link Tapo C520WS v2.6 before 1.2.4 Build 260326 Rel.24666n
Timeline
- 2026-04-02: disclosed
- 2026-04-02: advisory