CVE-2026-8714 Details
Description
A denial-of-service vulnerability exists in the RTSP server component of TP-Link Tapo C520WS v2 due to improper handling of syntactically invalid input. Crafted inputs can trigger a processing error, causing the RTSP service to enter non-responsive state. Successful exploitation may cause the RTSP in a denial-of-service condition.
A denial-of-service vulnerability has been identified in the RTSP server of the TP-Link Tapo C520WS v2 camera. This issue arises from improper handling of syntactically invalid input, which can cause the RTSP service to crash and become unresponsive. Exploitation of this vulnerability leads to a denial-of-service condition on the RTSP service.
Users are advised to update to the latest firmware version 1.2.6 Build 260528 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 5, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.tp-link.com/en/support/download/tapo-c520ws/v2/#Firmware-Release-Notes | TPLink | Product |
| https://www.tp-link.com/us/support/download/tapo-c520ws/v2/#Firmware-Release-Notes | TPLink | Product |
| https://www.tp-link.com/us/support/faq/5118/ | TPLink | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
| CWE-20 | Improper Input Validation | TPLink |
Affected Products
| Product | Versions |
|---|---|
| tp-link tapo c520ws firmware | < 1.2.6 |
CPE
Remediation
| |
| tp-link tapo c520ws | 2.0 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 19, 2026 | Initial Analysis | [email protected] |
| Jun 17, 2026 | CVE Modified | TPLink |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 5, 2026 | New CVE Received | TPLink |