Executive brief
A security vulnerability exists in the TP-Link Tapo C520WS outdoor security camera. An authorized user with high-level access can send a specially crafted command that causes the camera's management service to crash. This results in a denial-of-service, preventing the camera from being managed or operating normally until it is recovered.
Technical details
An authenticated format string vulnerability (CWE-134) exists in the ONVIF AddScopes method of the TP-Link Tapo C520WS v2. The vulnerability is caused by improperly passing user-controlled input from ONVIF scope parameters directly to formatting functions without adequate sanitization. An attacker with high privileges (PR:H) reachable via the adjacent network (AV:A) can inject format specifiers to manipulate memory handling. Successful exploitation leads to the termination of the ONVIF management service, resulting in a denial-of-service (DoS) condition affecting device operations.
Affected products
- TP-Link Tapo C520WS v2
Timeline
- 2026-06-05: disclosed
- 2026-06-06: advisory