CVE-2026-34124
TP-Link
- Published
- 2 April 2026
- Last modified
- 24 July 2026
- CVSS
- 7.1 v4.0
- Severity
- high
- EPSS
- 0.3% (22th pct)
- CISA KEV
- Not listed
- NVD status
- Analyzed
- Weaknesses
- CWE-120
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Description
A denial-of-service vulnerability was identified in TP-Link Tapo C520WS v2.6 within the HTTP request path parsing logic. The implementation enforces length restrictions on the raw request path but does not account for path expansion performed during normalization. An attacker on the adjacent network may send a crafted HTTP request to cause buffer overflow and memory corruption, leading to system interruption or device reboot.
Exploitation
Not listed in the CISA Known Exploited Vulnerabilities catalogue as of 2026.09.04. That is an absence of confirmed public exploitation, not evidence that exploitation has not occurred. EPSS models a 0.3% probability of exploitation activity in the next 30 days.
Affected products
| Product | Vendor | Type | Versions named |
|---|---|---|---|
| Tapo C520ws | TP-Link | unknown | 2, 2.0, 2.6, < 1.2.3 +2 |
References
Vendor advisory and patch
- https://www.tp-link.com/en/support/download/tapo-c520ws/#Firmware-Release-Notes
- https://www.tp-link.com/us/support/download/tapo-c520ws/#Firmware-Release-Notes
Record assembled from NVD, CISA KEV 2026.09.04 and FIRST EPSS 2026-09-04. Affected products are those NVD's CPE configuration names that fall inside this site's scope; a CVE may affect products outside it.