CVE-2026-34124: Denial of Service via Path Expansion Overflow in HTTP Service in TP-Link Tapo C520WS
A denial-of-service vulnerability was identified in TP-Link Tapo C520WS v2.6 within the HTTP request path parsing logic. The implementation enforces length restrictions on the raw request path but does not account for path expansion performed during normalization. An attacker on the adjacent network may send a crafted HTTP request to cause buffer overflow and memory corruption, leading to system interruption or device reboot.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-34124?
CVE-2026-34124 is classified as a denial-of-service vulnerability.
How do I fix CVE-2026-34124?
To fix CVE-2026-34124, you should update the TP-Link Tapo C520WS firmware to version 1.2.4 or later.
What systems are affected by CVE-2026-34124?
CVE-2026-34124 affects the TP-Link Tapo C520WS version 2.6 with firmware versions prior to 1.2.4.
What type of attack is associated with CVE-2026-34124?
CVE-2026-34124 is associated with a denial-of-service attack via path expansion overflow.
Can CVE-2026-34124 cause any data breaches?
CVE-2026-34124 primarily results in a denial of service and does not directly lead to data breaches.