NONE · 0

CVE-2026-6240

A stack-based buffer overflow vulnerability exists in Tapo C520WS v2 in the ONVIF DeleteUsers service, due to insufficient boundary checks when handling multiple user deletion parameters. An authentic...

Vulnerability Description

A stack-based buffer overflow vulnerability exists in Tapo C520WS v2 in the ONVIF DeleteUsers service, due to insufficient boundary checks when handling multiple user deletion parameters. An authenticated attacker can send a crafted malicious request containing an excessive number of identifiers to overflow stack memory. Successful exploitation may result in a service crash or deadlock, leading to DoS affecting device management and monitoring functionality.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-6240?

CVE-2026-6240 is a documented vulnerability. A stack-based buffer overflow vulnerability exists in Tapo C520WS v2 in the ONVIF DeleteUsers service, due to insufficient boundary checks when handling multiple user deletion parameters. An authentic...

How severe is CVE-2026-6240?

CVSS scoring is not yet available for CVE-2026-6240. Check NVD for updates.

Is there a patch for CVE-2026-6240?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.