CVE-2026-34119
Gravedad CVSS v4.0:
ALTA
Tipo:
CWE-122
Desbordamiento de búfer basado en memoria dinámica (Heap)
Fecha de publicación:
02/04/2026
Última modificación:
02/04/2026
Descripción
*** Pendiente de traducción *** A heap-based buffer overflow vulnerability was identified in TP-Link Tapo C520WS v2.6 within the HTTP parsing<br />
loop<br />
when appending segmented request bodies without<br />
continuous write‑boundary verification, due to insufficient boundary validation when handling externally supplied HTTP input. An attacker<br />
on the same network segment could trigger heap memory corruption conditions by<br />
sending crafted payloads that cause write operations beyond allocated buffer<br />
boundaries. Successful exploitation<br />
causes a Denial-of-Service (DoS) condition, causing the device’s process to<br />
crash or become unresponsive.
Impacto
Puntuación base 4.0
7.10
Gravedad 4.0
ALTA



