Heap-Based Buffer Overflow Vulnerability in TP-Link Tapo C520WS
CVE-2026-34120
7.1HIGH
What is CVE-2026-34120?
A heap-based buffer overflow vulnerability exists in TP-Link Tapo C520WS v2.6, arising from improper alignment and insufficient validation of buffer boundaries during the asynchronous parsing of local video streams. This weakness allows an attacker on the same network segment to exploit the device by sending specially crafted payloads, leading to memory corruption. The successful execution of this attack can result in a Denial-of-Service condition, causing the device to crash or become unresponsive.
Affected Version(s)
Tapo C520WS v2.6 0 < 1.2.4 Build 260326 Rel.24666n
