CVE-2026-34124
Gravedad CVSS v4.0:
ALTA
Tipo:
CWE-120
Copia de búfer sin comprobación del tamaño de entrada (Desbordamiento de búfer clásico)
Fecha de publicación:
02/04/2026
Última modificación:
03/04/2026
Descripción
*** Pendiente de traducción *** A denial-of-service vulnerability was identified in TP-Link Tapo C520WS v2.6 within the HTTP request path parsing logic. The implementation enforces length restrictions on the raw request path but does not account for path expansion performed during normalization. An attacker on the adjacent network may send a crafted HTTP request to cause buffer overflow and memory corruption, leading to system interruption or device reboot.
Impacto
Puntuación base 4.0
7.10
Gravedad 4.0
ALTA



