Executive brief
A security vulnerability exists in the TP-Link Tapo C520WS outdoor security camera that could allow an attacker on the same local network to crash the device. By sending a specially crafted web request, an attacker can cause the camera to stop functioning or reboot repeatedly. This disrupts continuous video monitoring and security recording, potentially leaving a property unmonitored.
Technical details
A classic buffer overflow (CWE-120) exists in the HTTP request path parsing logic of the TP-Link Tapo C520WS v2.6. While the firmware enforces length checks on raw incoming request paths, it fails to account for potential string expansion during the path normalization process. An unauthenticated attacker on the adjacent network can exploit this by sending a crafted HTTP request that expands beyond allocated buffer limits during processing. This results in memory corruption and a denial-of-service (DoS) condition, typically manifesting as a system crash or device reboot. The vulnerability is addressed in firmware version 1.2.4 Build 260326 Rel.24666n and later.
Affected products
- TP-Link Tapo C520WS v2.6 before 1.2.4 Build 260326 Rel.24666n
Timeline
- 2026-04-02: disclosed
- 2026-04-02: advisory
- 2026-04-02: patched: Fixed in version 1.2.4 Build 260326 Rel.24666n