{"schema_version":1,"title":"TP-Link Tapo C520WS vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 13 vulnerabilities in TP-Link Tapo C520WS: 0 in the last 7 days and 0 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-6242, was published on 6 June 2026.","url":"https://junglewise.ai/threats/technologies/tapo-c520ws","json_url":"https://junglewise.ai/threats/technologies/tapo-c520ws.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/tapo-c520ws","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":2,"all_time":13,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":0,"last_365_days":13},"latest":[{"cve":"CVE-2026-6242","cvss":6.8,"slug":"cve-2026-6242-tp-link-tapo-c520ws-format-string-vulnerability-in-onvif-subscribe","title":"TP-Link Tapo C520WS format string vulnerability in ONVIF Subscribe service","severity":"info","exploited":false,"published_at":"2026-06-06T00:16:41.347+00:00","url":"https://junglewise.ai/threats/cve-2026-6242-tp-link-tapo-c520ws-format-string-vulnerability-in-onvif-subscribe"},{"cve":"CVE-2026-6241","cvss":6.8,"slug":"cve-2026-6241-tp-link-tapo-c520ws-format-string-vulnerability-in-onvif-addscopes","title":"TP-Link Tapo C520WS format string vulnerability in ONVIF AddScopes","severity":"info","exploited":false,"published_at":"2026-06-06T00:16:41.23+00:00","url":"https://junglewise.ai/threats/cve-2026-6241-tp-link-tapo-c520ws-format-string-vulnerability-in-onvif-addscopes"},{"cve":"CVE-2026-6240","cvss":6.8,"slug":"cve-2026-6240-tp-link-tapo-c520ws-stack-overflow-in-onvif-deleteusers-service","title":"TP-Link Tapo C520WS stack overflow in ONVIF DeleteUsers service","severity":"info","exploited":false,"published_at":"2026-06-06T00:16:41.103+00:00","url":"https://junglewise.ai/threats/cve-2026-6240-tp-link-tapo-c520ws-stack-overflow-in-onvif-deleteusers-service"},{"cve":"CVE-2026-6239","cvss":6.8,"slug":"cve-2026-6239-tp-link-tapo-c520ws-stack-buffer-overflow-in-onvif-createusers","title":"TP-Link Tapo C520WS stack buffer overflow in ONVIF CreateUsers service","severity":"info","exploited":false,"published_at":"2026-06-06T00:16:40.977+00:00","url":"https://junglewise.ai/threats/cve-2026-6239-tp-link-tapo-c520ws-stack-buffer-overflow-in-onvif-createusers"},{"cve":"CVE-2026-34123","cvss":7,"slug":"cve-2026-34123-tp-link-tapo-c520ws-auth-bypass-in-api-authorization-mechanism","title":"TP-Link Tapo C520WS auth bypass in API authorization mechanism","severity":"info","exploited":false,"published_at":"2026-06-06T00:16:40.833+00:00","url":"https://junglewise.ai/threats/cve-2026-34123-tp-link-tapo-c520ws-auth-bypass-in-api-authorization-mechanism"},{"cve":"CVE-2026-8714","cvss":7.1,"slug":"cve-2026-8714-tp-link-tapo-c520ws-denial-of-service-in-rtsp-server","title":"TP-Link Tapo C520WS denial of service in RTSP server","severity":"info","exploited":false,"published_at":"2026-06-05T17:17:04.097+00:00","url":"https://junglewise.ai/threats/cve-2026-8714-tp-link-tapo-c520ws-denial-of-service-in-rtsp-server"},{"cve":"CVE-2026-34124","cvss":6.5,"epss":0.003,"slug":"cve-2026-34124-tp-link-tapo-c520ws-buffer-overflow-in-http-path-parsing","title":"TP-Link Tapo C520WS buffer overflow in HTTP path parsing","severity":"medium","exploited":false,"published_at":"2026-04-02T18:16:29.31+00:00","url":"https://junglewise.ai/threats/cve-2026-34124-tp-link-tapo-c520ws-buffer-overflow-in-http-path-parsing"},{"cve":"CVE-2026-34122","cvss":6.5,"epss":0.0026,"slug":"cve-2026-34122-tp-link-tapo-c520ws-stack-overflow-in-configuration-handling","title":"TP-Link Tapo C520WS stack overflow in configuration handling","severity":"medium","exploited":false,"published_at":"2026-04-02T18:16:29.15+00:00","url":"https://junglewise.ai/threats/cve-2026-34122-tp-link-tapo-c520ws-stack-overflow-in-configuration-handling"},{"cve":"CVE-2026-34121","cvss":8.8,"epss":0.0045,"slug":"cve-2026-34121-tp-link-tapo-c520ws-authentication-bypass-in-ds-configuration","title":"TP-Link Tapo C520WS authentication bypass in DS configuration service","severity":"high","exploited":false,"published_at":"2026-04-02T18:16:28.99+00:00","url":"https://junglewise.ai/threats/cve-2026-34121-tp-link-tapo-c520ws-authentication-bypass-in-ds-configuration"},{"cve":"CVE-2026-34120","cvss":6.5,"epss":0.0023,"slug":"cve-2026-34120-tp-link-tapo-c520ws-heap-overflow-in-video-stream-parsing","title":"TP-Link Tapo C520WS heap overflow in video stream parsing","severity":"medium","exploited":false,"published_at":"2026-04-02T18:16:28.827+00:00","url":"https://junglewise.ai/threats/cve-2026-34120-tp-link-tapo-c520ws-heap-overflow-in-video-stream-parsing"},{"cve":"CVE-2026-34119","cvss":6.5,"epss":0.0023,"slug":"cve-2026-34119-tp-link-tapo-c520ws-heap-overflow-in-http-parsing-loop","title":"TP-Link Tapo C520WS heap overflow in HTTP parsing loop","severity":"medium","exploited":false,"published_at":"2026-04-02T18:16:28.68+00:00","url":"https://junglewise.ai/threats/cve-2026-34119-tp-link-tapo-c520ws-heap-overflow-in-http-parsing-loop"},{"cve":"CVE-2026-34118","cvss":6.5,"epss":0.0026,"slug":"cve-2026-34118-tp-link-tapo-c520ws-heap-overflow-in-http-post-parsing","title":"TP-Link Tapo C520WS heap overflow in HTTP POST parsing","severity":"medium","exploited":false,"published_at":"2026-04-02T18:16:28.503+00:00","url":"https://junglewise.ai/threats/cve-2026-34118-tp-link-tapo-c520ws-heap-overflow-in-http-post-parsing"},{"cve":"CVE-2026-0651","cvss":7.8,"epss":0.0032,"slug":"cve-2026-0651-tp-link-tapo-camera-path-traversal-in-http-server","title":"TP-Link Tapo camera path traversal in HTTP server","severity":"high","exploited":false,"published_at":"2026-02-10T18:16:21.977+00:00","url":"https://junglewise.ai/threats/cve-2026-0651-tp-link-tapo-camera-path-traversal-in-http-server"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"TP-Link TL-WR841N","slug":"tl-wr841n","vulnerabilities":8,"url":"https://junglewise.ai/threats/technologies/tl-wr841n"},{"name":"TP-Link Archer AX53","slug":"archer-ax53","vulnerabilities":7,"url":"https://junglewise.ai/threats/technologies/archer-ax53"},{"name":"TP-Link Archer Ax53 Firmware","slug":"archer-ax53-firmware","vulnerabilities":7,"url":"https://junglewise.ai/threats/technologies/archer-ax53-firmware"},{"name":"TP-Link Multiple Routers","slug":"multiple-routers","vulnerabilities":6,"url":"https://junglewise.ai/threats/technologies/multiple-routers"},{"name":"TP-Link Tapo C520WS firmware","slug":"tapo-c520ws-firmware","vulnerabilities":6,"url":"https://junglewise.ai/threats/technologies/tapo-c520ws-firmware"},{"name":"TP-Link TL-MR6400","slug":"tl-mr6400","vulnerabilities":6,"url":"https://junglewise.ai/threats/technologies/tl-mr6400"},{"name":"TP-Link Archer MR600","slug":"archer-mr600","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/archer-mr600"},{"name":"TP-Link Archer BE230","slug":"archer-be230","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/archer-be230"},{"name":"TP-Link Archer Be230 Firmware","slug":"archer-be230-firmware","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/archer-be230-firmware"},{"name":"TP-Link Archer BE3600","slug":"archer-be3600","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/archer-be3600"},{"name":"TP-Link Deco BE23","slug":"deco-be23","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/deco-be23"},{"name":"TP-Link Deco BE25","slug":"deco-be25","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/deco-be25"}],"technology":{"hub":true,"name":"TP-Link Tapo C520WS","slug":"tapo-c520ws","vendor":{"name":"TP-Link","slug":"tp-link","url":"https://junglewise.ai/threats/vendors/tp-link"},"aliases":[],"category":"firmware","homepage":"https://www.tp-link.com/home-networking/cloud-camera/tapo-c520ws/","repo_url":"https://www.tp-link.com/us/smart-home/tapo/tapo-c520ws/","description":"Firmware for an outdoor pan-tilt security Wi-Fi camera.","url":"https://junglewise.ai/threats/technologies/tapo-c520ws"},"most_severe":[{"cve":"CVE-2026-34121","cvss":8.8,"epss":0.0045,"slug":"cve-2026-34121-tp-link-tapo-c520ws-authentication-bypass-in-ds-configuration","title":"TP-Link Tapo C520WS authentication bypass in DS configuration service","severity":"high","exploited":false,"published_at":"2026-04-02T18:16:28.99+00:00","url":"https://junglewise.ai/threats/cve-2026-34121-tp-link-tapo-c520ws-authentication-bypass-in-ds-configuration"},{"cve":"CVE-2026-0651","cvss":7.8,"epss":0.0032,"slug":"cve-2026-0651-tp-link-tapo-camera-path-traversal-in-http-server","title":"TP-Link Tapo camera path traversal in HTTP server","severity":"high","exploited":false,"published_at":"2026-02-10T18:16:21.977+00:00","url":"https://junglewise.ai/threats/cve-2026-0651-tp-link-tapo-camera-path-traversal-in-http-server"},{"cve":"CVE-2026-34124","cvss":6.5,"epss":0.003,"slug":"cve-2026-34124-tp-link-tapo-c520ws-buffer-overflow-in-http-path-parsing","title":"TP-Link Tapo C520WS buffer overflow in HTTP path parsing","severity":"medium","exploited":false,"published_at":"2026-04-02T18:16:29.31+00:00","url":"https://junglewise.ai/threats/cve-2026-34124-tp-link-tapo-c520ws-buffer-overflow-in-http-path-parsing"},{"cve":"CVE-2026-34122","cvss":6.5,"epss":0.0026,"slug":"cve-2026-34122-tp-link-tapo-c520ws-stack-overflow-in-configuration-handling","title":"TP-Link Tapo C520WS stack overflow in configuration handling","severity":"medium","exploited":false,"published_at":"2026-04-02T18:16:29.15+00:00","url":"https://junglewise.ai/threats/cve-2026-34122-tp-link-tapo-c520ws-stack-overflow-in-configuration-handling"},{"cve":"CVE-2026-34118","cvss":6.5,"epss":0.0026,"slug":"cve-2026-34118-tp-link-tapo-c520ws-heap-overflow-in-http-post-parsing","title":"TP-Link Tapo C520WS heap overflow in HTTP POST parsing","severity":"medium","exploited":false,"published_at":"2026-04-02T18:16:28.503+00:00","url":"https://junglewise.ai/threats/cve-2026-34118-tp-link-tapo-c520ws-heap-overflow-in-http-post-parsing"},{"cve":"CVE-2026-34120","cvss":6.5,"epss":0.0023,"slug":"cve-2026-34120-tp-link-tapo-c520ws-heap-overflow-in-video-stream-parsing","title":"TP-Link Tapo C520WS heap overflow in video stream parsing","severity":"medium","exploited":false,"published_at":"2026-04-02T18:16:28.827+00:00","url":"https://junglewise.ai/threats/cve-2026-34120-tp-link-tapo-c520ws-heap-overflow-in-video-stream-parsing"},{"cve":"CVE-2026-34119","cvss":6.5,"epss":0.0023,"slug":"cve-2026-34119-tp-link-tapo-c520ws-heap-overflow-in-http-parsing-loop","title":"TP-Link Tapo C520WS heap overflow in HTTP parsing loop","severity":"medium","exploited":false,"published_at":"2026-04-02T18:16:28.68+00:00","url":"https://junglewise.ai/threats/cve-2026-34119-tp-link-tapo-c520ws-heap-overflow-in-http-parsing-loop"},{"cve":"CVE-2026-8714","cvss":7.1,"slug":"cve-2026-8714-tp-link-tapo-c520ws-denial-of-service-in-rtsp-server","title":"TP-Link Tapo C520WS denial of service in RTSP server","severity":"info","exploited":false,"published_at":"2026-06-05T17:17:04.097+00:00","url":"https://junglewise.ai/threats/cve-2026-8714-tp-link-tapo-c520ws-denial-of-service-in-rtsp-server"},{"cve":"CVE-2026-34123","cvss":7,"slug":"cve-2026-34123-tp-link-tapo-c520ws-auth-bypass-in-api-authorization-mechanism","title":"TP-Link Tapo C520WS auth bypass in API authorization mechanism","severity":"info","exploited":false,"published_at":"2026-06-06T00:16:40.833+00:00","url":"https://junglewise.ai/threats/cve-2026-34123-tp-link-tapo-c520ws-auth-bypass-in-api-authorization-mechanism"},{"cve":"CVE-2026-6242","cvss":6.8,"slug":"cve-2026-6242-tp-link-tapo-c520ws-format-string-vulnerability-in-onvif-subscribe","title":"TP-Link Tapo C520WS format string vulnerability in ONVIF Subscribe service","severity":"info","exploited":false,"published_at":"2026-06-06T00:16:41.347+00:00","url":"https://junglewise.ai/threats/cve-2026-6242-tp-link-tapo-c520ws-format-string-vulnerability-in-onvif-subscribe"}],"generated_at":"2026-09-26T09:11:00.170868+00:00"}