CVE-2026-34119 Details
Description
A heap-based buffer overflow vulnerability was identified in TP-Link Tapo C520WS v2.6 within the HTTP parsing loop when appending segmented request bodies without continuous write‑boundary verification, due to insufficient boundary validation when handling externally supplied HTTP input. An attacker on the same network segment could trigger heap memory corruption conditions by sending crafted payloads that cause write operations beyond allocated buffer boundaries. Successful exploitation causes a Denial-of-Service (DoS) condition, causing the device’s process to crash or become unresponsive.
A heap-based buffer overflow vulnerability has been identified in the TP-Link Tapo C520WS camera, specifically in version 2.6. The vulnerability arises in the HTTP parsing loop, where segmented request bodies are appended without proper verification of write boundaries. This lack of continuous boundary validation allows an attacker on the same network segment to send crafted payloads that corrupt heap memory by writing beyond the limits of allocated buffers. Successful exploitation of this vulnerability causes a Denial-of-Service condition, crashing or freezing the device's process.
Users are advised to update to the latest firmware version. The updated firmware can be downloaded from the TP-Link website.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 3, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.tp-link.com/en/support/download/tapo-c520ws/#Firmware-Release-Notes | TPLink | Release Notes |
| https://www.tp-link.com/us/support/download/tapo-c520ws/#Firmware-Release-Notes | TPLink | Release Notes |
| https://www.tp-link.com/us/support/faq/5047/ | TPLink | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-122 | Heap-based Buffer Overflow | TPLink |
Affected Products
| Product | Versions |
|---|---|
| tp-link tapo c520ws firmware | < 1.2.4 |
CPE
Remediation
| |
| tp-link tapo c520ws | 2.6 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | TPLink |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 6, 2026 | Initial Analysis | [email protected] |
| Apr 2, 2026 | New CVE Received | TPLink |