---
id: CVE-2026-34118
title: "A heap-based buffer overflow vulnerability was identified in TP-Link Tapo C100/C101 v5, C520WS v2.6\_in the HTTP POST body parsing logic due to missing validation of remaining buffer capacity after dynamic allocation, due to\_insufficient …"
summary: "A heap-based buffer overflow vulnerability was identified in TP-Link Tapo C100/C101 v5, C520WS v2.6\_in the HTTP POST body parsing logic due to missing validation of remaining buffer capacity after dynamic allocation, due to\_insufficient …"
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-122
vendor: tp-link
product: tapo_c520ws_firmware
affected:
  - tapo_c520ws_firmware < 1.2.4
patched:
  - tapo_c520ws_firmware 1.2.4
published: '2026-04-02'
updated: '2026-08-19'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-34118'
references:
  - url: >-
      https://www.tp-link.com/en/support/download/tapo-c100/v5/#Firmware-Release-Notes
    label: f23511db-6c3e-4e32-a477-6aa17d310630
  - url: >-
      https://www.tp-link.com/en/support/download/tapo-c520ws/#Firmware-Release-Notes
    label: f23511db-6c3e-4e32-a477-6aa17d310630
  - url: >-
      https://www.tp-link.com/us/support/download/tapo-c100/v5/#Firmware-Release-Notes
    label: f23511db-6c3e-4e32-a477-6aa17d310630
  - url: >-
      https://www.tp-link.com/us/support/download/tapo-c101/v5/#Firmware-Release-Notes
    label: f23511db-6c3e-4e32-a477-6aa17d310630
  - url: >-
      https://www.tp-link.com/us/support/download/tapo-c520ws/#Firmware-Release-Notes
    label: f23511db-6c3e-4e32-a477-6aa17d310630
  - url: 'https://www.tp-link.com/us/support/faq/5047/'
    label: f23511db-6c3e-4e32-a477-6aa17d310630
tags:
  - nvd
epss: 0.00516
epssPercentile: 0.41438
ingestedAt: '2026-08-20T17:59:04.705Z'
---

## Overview

A heap-based buffer overflow vulnerability was identified in TP-Link Tapo C100/C101 v5, C520WS v2.6 in the HTTP POST body parsing logic due to missing validation of remaining buffer capacity after dynamic allocation, due to insufficient boundary validation when handling externally supplied HTTP input.  

An attacker
on the same network segment could trigger heap memory corruption conditions by
sending crafted payloads that cause write operations beyond allocated buffer
boundaries.  Successful exploitation
causes a Denial-of-Service (DoS) condition, causing the device’s process to
crash or become unresponsive.

## Affected

- `tapo_c520ws_firmware < 1.2.4`

## Remediation

Upgrade past the affected range:

- `tapo_c520ws_firmware 1.2.4`
