Back to CVE List

CVE-2026-34124

MEDIUM SEVERITY

CVSS Score & Metrics

Base Score
6.5 / 10
Vector String
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Vulnerability Description

A denial-of-service vulnerability was identified in TP-Link Tapo C520WS v2.6 within the HTTP request path parsing logic. The implementation enforces length restrictions on the raw request path but does not account for path expansion performed during normalization. An attacker on the adjacent network may send a crafted HTTP request to cause buffer overflow and memory corruption, leading to system interruption or device reboot.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-120
Source
NVD
Vendor
TP-Link Systems Inc.
Product
Tapo C520WS v2.6

External References

Discussion (0)

Add Comment

No comments yet. Be the first!