Junglewise Threat Intelligence

CVE-2026-6242: TP-Link Tapo C520WS format string vulnerability in ONVIF Subscribe service

CVE-2026-6242 · Severity: info · CVSS 6.8 · Published 2026-06-06

Technologies: TP-Link Tapo C520WS. Vendors: TP-Link.

Executive brief

A security vulnerability exists in the TP-Link Tapo C520WS outdoor security camera. An authorized user can send a specially crafted request to the camera's event subscription service that causes it to crash. If exploited, the camera will stop sending real-time motion alerts and alarm notifications, effectively disabling its primary security monitoring functions.

Technical details

An authenticated format string vulnerability (CWE-134) exists in the ONVIF Subscribe service of the TP-Link Tapo C520WS v2. The flaw is caused by improper handling of externally supplied parameters within formatting functions during the processing of event subscription requests or notification generation. An attacker with high privileges can inject crafted format specifiers into these requests to trigger a service crash. Successful exploitation results in the termination of the event notification service, leading to a loss of real-time alarm functionality. The vulnerability is reachable via the adjacent network.

Affected products

  • TP-Link Tapo C520WS v2

Timeline

  • 2026-06-06: advisory: TP-Link and NVD published the advisory.

References

Related threats