CVE Explorer
CVE-2026-6239
A stack‑based
buffer overflow vulnerability exists in Tapo C520WS v2 in the ONVIF CreateUsers service, where
the device fails to properly validate the number of XML user nodes during
request processing. An authenticated attacker can send a specially crafted
ONVIF request containing an excessive number of user entries to trigger memory
corruption.
Successful
exploitation may cause the ONVIF management service to terminate unexpectedly,
resulting in a denial‑of‑service (DoS) condition tha
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","product":"Tapo C520WS v2","vendor":"TP-Link Systems Inc.","versions":[{"lessThan":"1.2.6 Build 260528","status":"affected","version":"0","versionType":"custom"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:073a6fc46238007ae7781bbfe11c4d88ceb62ad90b985254fbb8cd53a300a2c7 · sha256:ed84c499c74e0c7f… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"ADJACENT","baseScore":6.8,"baseSeverity":"MEDIUM","exploitMaturity":"NOT_DEFINED","privilegesRequired":"HIGH","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpact…
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:073a6fc46238007ae7781bbfe11c4d88ceb62ad90b985254fbb8cd53a300a2c7 · sha256:ed84c499c74e0c7f… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-121","description":"CWE-121 Stack-based buffer overflow","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:073a6fc46238007ae7781bbfe11c4d88ceb62ad90b985254fbb8cd53a300a2c7 · sha256:ed84c499c74e0c7f… · /containers/cna/problemTypes/0/descriptions/0
Source references
3 source assertions{"tags":["patch"],"url":"https://www.tp-link.com/en/support/download/tapo-c520ws/#Firmware-Release-Notes"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:073a6fc46238007ae7781bbfe11c4d88ceb62ad90b985254fbb8cd53a300a2c7 · sha256:ed84c499c74e0c7f… · /containers/cna/references/1
{"tags":["patch"],"url":"https://www.tp-link.com/us/support/download/tapo-c520ws/#Firmware-Release-Notes"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:073a6fc46238007ae7781bbfe11c4d88ceb62ad90b985254fbb8cd53a300a2c7 · sha256:ed84c499c74e0c7f… · /containers/cna/references/0
{"tags":["vendor-advisory"],"url":"https://www.tp-link.com/us/support/faq/5120/"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:073a6fc46238007ae7781bbfe11c4d88ceb62ad90b985254fbb8cd53a300a2c7 · sha256:ed84c499c74e0c7f… · /containers/cna/references/2
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.