216.73.216.36

CVE-2026-6240

· Published 06/06/2026 00:16 · Modified 06/06/2026 00:16

Labels: CVE-2026-6240 2026-06-06CVE-2026-6240CWE-121f23511db-6c3e-4e32-a477-6aa17d310630

Essential information

Published
06/06/2026 00:16
Modified
06/06/2026 00:16
Author
Creator
CVSS
6.8 MEDIUM (v3) 6.8 MEDIUM (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

A stack-based buffer overflow vulnerability exists in Tapo C520WS v2 in the ONVIF DeleteUsers service, due to insufficient boundary checks when handling multiple user deletion parameters. An authenticated attacker can send a crafted malicious request containing an excessive number of identifiers to overflow stack memory. Successful exploitation may result in a service crash or deadlock, leading to DoS affecting device management and monitoring functionality.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
f23511db-6c3e-4e32-a477-6aa17d310630
NVD
View on NVD

Affected products (CPE)

ProductCPE
tp-link / tapo c520ws cpe:2.3:a:tp-link:tapo_c520ws:2:*:*:*:*:*:*:*

References