Executive brief
A security vulnerability has been identified in the TP-Link Tapo C520WS, a popular outdoor security camera. An attacker on the same local network could send specially crafted data to the device to cause it to crash or become unresponsive. This results in a denial-of-service, effectively disabling the camera's ability to monitor or record video until it is recovered.
Technical details
A heap-based buffer overflow (CWE-122) exists in the TP-Link Tapo C520WS v2.6 within the asynchronous parsing of local video stream content. The vulnerability is caused by insufficient alignment and validation of buffer boundaries when processing streaming inputs. An attacker located on the same network segment (adjacent) can trigger heap memory corruption by sending crafted payloads that result in out-of-bounds write operations. Successful exploitation leads to a denial-of-service (DoS) where the device process crashes or becomes unresponsive. The issue is addressed in firmware version 1.2.4 Build 260326 Rel.24666n and later.
Affected products
- TP-Link Tapo C520WS firmware before 1.2.4 Build 260326 Rel.24666n
Timeline
- 2026-04-02: disclosed
- 2026-04-02: advisory