Description
A stack‑based
buffer overflow vulnerability exists in Tapo C520WS v2 in the ONVIF CreateUsers service, where
the device fails to properly validate the number of XML user nodes during
request processing. An authenticated attacker can send a specially crafted
ONVIF request containing an excessive number of user entries to trigger memory
corruption.









Successful
exploitation may cause the ONVIF management service to terminate unexpectedly,
resulting in a denial‑of‑service (DoS) condition that disrupts device
configuration and management functions.
Published: 2026-06-05
Score: 6.8 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is a stack‑based buffer overflow that occurs in the ONVIF CreateUsers service on the Tapo C520WS v2. When the device processes an ONVIF request, it does not enforce a limit on the number of XML user nodes, allowing a crafted request with many entries to overflow a buffer. The overflow can corrupt memory and crash the ONVIF management service, which the device relies on for configuration and management functions. Consequently, an attacker can force the service to crash, impairing remote management and potentially affecting the overall stability of the device. The weakness is classified as CWE‑121, indicating a stack exploitation scenario.

Affected Systems

The affected product is the TP‑Link Tapo C520WS v2. No other versions or vendors are listed. The device runs firmware that includes the vulnerable ONVIF CreateUsers service and has been identified in the manufacturer’s firmware release notes.

Risk and Exploitability

The CVSS score of 6.8 indicates moderate severity. Since EPSS data is unavailable, the likelihood of exploitation cannot be quantified, but the vulnerability requires authentication, implying the attacker must first gain authorized access to the device or the ONVIF service. The vulnerability is not listed in CISA's KEV catalog, so no known widespread exploit activity is reported. Attackers with remote administrative credentials or local network access can send the specially crafted request, possibly leading to service termination and a denial‑of‑service condition. Properly patching the firmware or disabling the vulnerable service mitigates this risk.

Generated by OpenCVE AI on June 6, 2026 at 01:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and install the latest firmware update for TP‑Link Tapo C520WS v2 from the official support site.
  • Disable or restrict access to the ONVIF service using firewall rules or service configuration if the device’s firmware does not allow disabling.
  • Monitor the ONVIF service logs for abnormal termination events and verify that the service remains operational after updates.

Generated by OpenCVE AI on June 6, 2026 at 01:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 06 Jun 2026 00:15:00 +0000

Type Values Removed Values Added
Description A stack‑based buffer overflow vulnerability exists in Tapo C520WS v2 in the ONVIF CreateUsers service, where the device fails to properly validate the number of XML user nodes during request processing. An authenticated attacker can send a specially crafted ONVIF request containing an excessive number of user entries to trigger memory corruption. Successful exploitation may cause the ONVIF management service to terminate unexpectedly, resulting in a denial‑of‑service (DoS) condition that disrupts device configuration and management functions.
Title Authenticated Stack-based Buffer Overflow in ONVIF CreateUsers Service in TP-Link Tao C520WS
Weaknesses CWE-121
References
Metrics cvssV4_0

{'score': 6.8, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: TPLink

Published:

Updated: 2026-06-05T23:50:59.001Z

Reserved: 2026-04-13T17:10:22.074Z

Link: CVE-2026-6239

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-06-06T00:16:40.977

Modified: 2026-06-06T00:16:40.977

Link: CVE-2026-6239

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-06T01:30:06Z

Weaknesses