Junglewise Threat Intelligence

CVE-2026-6240: TP-Link Tapo C520WS stack overflow in ONVIF DeleteUsers service

CVE-2026-6240 · Severity: info · CVSS 6.8 · Published 2026-06-06

Technologies: TP-Link Tapo C520WS. Vendors: TP-Link.

Executive brief

A security vulnerability exists in the TP-Link Tapo C520WS security camera, a device used for home and business monitoring. An authorized user can cause the camera's management software to crash or freeze by sending a specially crafted request to delete users. This results in a denial-of-service, preventing owners from managing the device or viewing monitoring feeds until the system is recovered.

Technical details

A stack-based buffer overflow (CWE-121) exists in the ONVIF DeleteUsers service of the TP-Link Tapo C520WS v2. The vulnerability is caused by insufficient boundary checks when the service handles multiple user deletion parameters. An authenticated attacker with high privileges can exploit this by sending a crafted ONVIF request containing an excessive number of identifiers. Successful exploitation leads to memory corruption, resulting in a service crash or deadlock (Denial of Service). The attack vector is restricted to the adjacent network (AV:A). Firmware updates are typically available through the Tapo mobile application.

Affected products

  • TP-Link Tapo C520WS v2

Timeline

  • 2026-06-05: disclosed: Initial disclosure by TP-Link
  • 2026-06-06: advisory: NVD publication date

References

Related threats