Junglewise Threat Intelligence

CVE-2026-34122: TP-Link Tapo C520WS stack overflow in configuration handling

CVE-2026-34122 · Severity: medium · CVSS 6.5 · Published 2026-04-02

Technologies: TP-Link Tapo C520WS, TP-Link Tapo C520ws Firmware. Vendors: TP-Link.

Executive brief

A security vulnerability exists in the TP-Link Tapo C520WS outdoor security camera. An attacker on the same local network can send a specially crafted configuration request to the device, causing it to crash or reboot. This results in a denial-of-service, preventing the camera from recording video or providing security monitoring until it is restored.

Technical details

A stack-based buffer overflow (CWE-121) exists in the configuration handling component of TP-Link Tapo C520WS v2.6 firmware. The vulnerability is caused by insufficient input validation when processing configuration parameters. An attacker with adjacent network access can exploit this by supplying an excessively long value for a vulnerable parameter, leading to a stack overflow. Successful exploitation results in a service crash or device reboot (Denial of Service). The issue is addressed in firmware version 1.2.4 Build 260326 Rel.24666n and later.

Affected products

  • TP-Link Tapo C520WS v2.6 before 1.2.4 Build 260326 Rel.24666n

Timeline

  • 2026-04-02: disclosed
  • 2026-04-02: advisory

References

Related threats