Junglewise Threat Intelligence

CVE-2026-6241: TP-Link Tapo C520WS format string vulnerability in ONVIF AddScopes

CVE-2026-6241 · Severity: info · CVSS 6.8 · Published 2026-06-06

Technologies: TP-Link Tapo C520WS. Vendors: TP-Link.

Executive brief

A security vulnerability exists in the TP-Link Tapo C520WS outdoor security camera. An authorized user with high-level access can send a specially crafted command that causes the camera's management service to crash. This results in a denial-of-service, preventing the camera from being managed or operating normally until it is recovered.

Technical details

An authenticated format string vulnerability (CWE-134) exists in the ONVIF AddScopes method of the TP-Link Tapo C520WS v2. The vulnerability is caused by improperly passing user-controlled input from ONVIF scope parameters directly to formatting functions without adequate sanitization. An attacker with high privileges (PR:H) reachable via the adjacent network (AV:A) can inject format specifiers to manipulate memory handling. Successful exploitation leads to the termination of the ONVIF management service, resulting in a denial-of-service (DoS) condition affecting device operations.

Affected products

  • TP-Link Tapo C520WS v2

Timeline

  • 2026-06-05: disclosed
  • 2026-06-06: advisory

References

Related threats