Executive brief
The TP-Link Tapo C520WS is an outdoor security camera. A vulnerability in its user management service allows an authorized user to crash the device's management functions by sending a specially crafted request. This results in a denial-of-service condition, preventing the camera from being configured or managed until the service is restored.
Technical details
A stack-based buffer overflow (CWE-121) exists in the ONVIF CreateUsers service of the TP-Link Tapo C520WS v2. The vulnerability is caused by a failure to properly validate the number of XML user nodes during request processing. An authenticated attacker with high privileges can exploit this by sending a specially crafted ONVIF request containing an excessive number of user entries. This triggers memory corruption, leading to the unexpected termination of the ONVIF management service and a subsequent denial-of-service (DoS) affecting device configuration and management. The attack vector is classified as 'Adjacent' (AV:A) per the vendor's CVSS 4.0 string.
Affected products
- TP-Link Tapo C520WS v2
Timeline
- 2026-06-05: advisory: NVD and TP-Link published advisory details.
- 2026-06-06: disclosed