CVE-2026-34124
MEDIUM SEVERITYCVSS Score & Metrics
Base Score
6.5 / 10
Vector String
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Vulnerability Description
A denial-of-service vulnerability was identified in TP-Link Tapo C520WS v2.6 within the HTTP request path parsing logic. The implementation enforces length restrictions on the raw request path but does not account for path expansion performed during normalization. An attacker on the adjacent network may send a crafted HTTP request to cause buffer overflow and memory corruption, leading to system interruption or device reboot.
Vulnerability Details
Published Date
Last Modified
CWE ID
CWE-120
Source
NVD
Vendor
TP-Link Systems Inc.
Product
Tapo C520WS v2.6
Discussion (0)
Add Comment
No comments yet. Be the first!