Impact
A heap-based buffer overflow vulnerability was identified in TP‑Link Tapo C100/C101 v5 and Tapo C520WS v2.6 in the HTTP POST body parsing logic due to missing validation of remaining buffer capacity after dynamic allocation, and due to insufficient boundary validation when handling externally supplied HTTP input. An attacker on the same network segment can trigger heap memory corruption by sending crafted payloads that cause write operations beyond the allocated buffer boundaries. Successful exploitation causes a denial‑of‑service condition, with the device’s process crashing or becoming unresponsive.
Affected Systems
TP‑Link Tapo C100 v5, Tapo C101 v5, and Tapo C520WS v2.6 are all listed as affected. No other devices or firmware versions are referenced as vulnerable in the available information.
Risk and Exploitability
The CVSS score of 7.1 indicates moderate to high impact, while the EPSS score of less than 1% implies a low probability of widespread exploitation. The flaw is not cataloged in CISA's list of known exploited vulnerabilities. Attack requires local network access and involves sending malicious HTTP POST payloads from any host on the same segment. An attacker who can reach the camera can trigger a crash without gaining further access to the device or its network.
OpenCVE Enrichment