CVE-2026-34124 Details
Description
A denial-of-service vulnerability was identified in TP-Link Tapo C520WS v2.6 within the HTTP request path parsing logic. The implementation enforces length restrictions on the raw request path but does not account for path expansion performed during normalization. An attacker on the adjacent network may send a crafted HTTP request to cause buffer overflow and memory corruption, leading to system interruption or device reboot.
A denial-of-service vulnerability exists in the TP-Link Tapo C520WS camera, version 2.6, due to improper handling of HTTP request paths. The vulnerability arises because the device enforces length limits on raw request paths but fails to consider path expansion during normalization. An attacker on the same network can exploit this by sending a crafted HTTP request that causes a buffer overflow and memory corruption, leading to a system crash or device reboot.
Users are advised to update to the latest firmware version. The updated firmware can be downloaded from the TP-Link website, either from the US or the international page.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 3, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.tp-link.com/en/support/download/tapo-c520ws/#Firmware-Release-Notes | TPLink | Release Notes |
| https://www.tp-link.com/us/support/download/tapo-c520ws/#Firmware-Release-Notes | TPLink | Release Notes |
| https://www.tp-link.com/us/support/faq/5047/ | TPLink | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-120 | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') | TPLink |
Affected Products
| Product | Versions |
|---|---|
| tp-link tapo c520ws firmware | < 1.2.4 |
CPE
Remediation
| |
| tp-link tapo c520ws | 2.6 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | TPLink |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 6, 2026 | Initial Analysis | [email protected] |
| Apr 2, 2026 | New CVE Received | TPLink |