Junglewise Threat Intelligence

CVE-2026-6239: TP-Link Tapo C520WS stack buffer overflow in ONVIF CreateUsers service

CVE-2026-6239 · Severity: info · CVSS 6.8 · Published 2026-06-06

Technologies: TP-Link Tapo C520WS. Vendors: TP-Link.

Executive brief

The TP-Link Tapo C520WS is an outdoor security camera. A vulnerability in its user management service allows an authorized user to crash the device's management functions by sending a specially crafted request. This results in a denial-of-service condition, preventing the camera from being configured or managed until the service is restored.

Technical details

A stack-based buffer overflow (CWE-121) exists in the ONVIF CreateUsers service of the TP-Link Tapo C520WS v2. The vulnerability is caused by a failure to properly validate the number of XML user nodes during request processing. An authenticated attacker with high privileges can exploit this by sending a specially crafted ONVIF request containing an excessive number of user entries. This triggers memory corruption, leading to the unexpected termination of the ONVIF management service and a subsequent denial-of-service (DoS) affecting device configuration and management. The attack vector is classified as 'Adjacent' (AV:A) per the vendor's CVSS 4.0 string.

Affected products

  • TP-Link Tapo C520WS v2

Timeline

  • 2026-06-05: advisory: NVD and TP-Link published advisory details.
  • 2026-06-06: disclosed

References

Related threats