PT-2026-47079 · Tp Link · Tapo C520Ws V2

CVE-2026-6242

·

Published

2026-06-05

·

Updated

2026-06-06

CVSS v4.0

6.8

Medium

VectorAV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Tapo C520WS v2
Description An authenticated format string vulnerability exists in the ONVIF Subscribe service due to improper handling of externally supplied parameters within formatting functions. An attacker can inject crafted format strings into event subscription requests or the notification generation path to disrupt normal service execution. This may cause the event notification service to terminate unexpectedly, leading to the loss of real-time alarm functionality and disruption of event notifications.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Use of Externally-Controlled Format String

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-6242

Affected Products

Tapo C520Ws V2