August 10, 2026

CVE Watchtower


← Back to CVE List

CVE-2026-34124NVD

Vulnerability Summary

A denial-of-service vulnerability was identified in TP-Link Tapo C520WS v2.6 within the HTTP request path parsing logic. The implementation enforces length restrictions on the raw request path but does not account for path expansion performed during normalization. An attacker on the adjacent network may send a crafted HTTP request to cause buffer overflow and memory corruption, leading to system interruption or device reboot.
Severity Level
UNKNOWN
Published Date
Apr 2, 2026
Last Modified
Apr 3, 2026
Exploitation Status
No confirmed exploitation yet
EPSS Score (30-Day)
0.03%Probability
Root Weakness (CWE)
N/A