Heap-Based Buffer Overflow Vulnerability in TP-Link Tapo C520WS
CVE-2026-34120

7.1HIGH

What is CVE-2026-34120?

A heap-based buffer overflow vulnerability exists in TP-Link Tapo C520WS v2.6, arising from improper alignment and insufficient validation of buffer boundaries during the asynchronous parsing of local video streams. This weakness allows an attacker on the same network segment to exploit the device by sending specially crafted payloads, leading to memory corruption. The successful execution of this attack can result in a Denial-of-Service condition, causing the device to crash or become unresponsive.

Affected Version(s)

Tapo C520WS v2.6 0 < 1.2.4 Build 260326 Rel.24666n

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.