PT-2026-47079 · Tp Link · Tapo C520Ws V2
CVE-2026-6242
·
Published
2026-06-05
·
Updated
2026-06-06
CVSS v4.0
6.8
Medium
| Vector | AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Tapo C520WS v2
Description
An authenticated format string vulnerability exists in the ONVIF Subscribe service due to improper handling of externally supplied parameters within formatting functions. An attacker can inject crafted format strings into event subscription requests or the notification generation path to disrupt normal service execution. This may cause the event notification service to terminate unexpectedly, leading to the loss of real-time alarm functionality and disruption of event notifications.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Use of Externally-Controlled Format String
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tapo C520Ws V2