Executive brief
A security vulnerability has been identified in the TP-Link Tapo C520WS outdoor security camera. The flaw affects the component responsible for streaming video (RTSP), allowing an attacker on the same local network to crash the service. If exploited, the camera's video streaming capabilities will become unresponsive, potentially disabling remote monitoring and security recording.
Technical details
A denial-of-service (DoS) vulnerability exists in the RTSP server component of the TP-Link Tapo C520WS v2 security camera. The issue stems from improper input validation (CWE-20) when handling syntactically invalid RTSP requests. An attacker located on the adjacent network (local network) can send specially crafted inputs to trigger a processing error, causing the RTSP service to enter a non-responsive state. This effectively disables video streaming functionality until the service or device is restarted. The vulnerability is addressed in firmware version 1.2.6 Build 260528 Rel.60422n or later.
Affected products
- TP-Link Tapo C520WS v2 (prior to firmware 1.2.6 Build 260528 Rel.60422n)
Timeline
- 2026-06-05: disclosed
- 2026-06-05: advisory
- 2026-05-28: patched: Firmware build date for the fix