An authenticated format string vulnerability exists in the ONVIF Subscribe service in Tapo C520WS v2 due to improper handling of externally supplied parameters within formatting functions. An attacker may inject crafted format strings into event subscription requests or notification generation path to disrupt normal service execution. Successful exploitation may cause the event notification service to terminate unexpectedly, resulting in the loss of real-time alarm functionality and disruption of event notifications.
History

Mon, 08 Jun 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 07 Jun 2026 11:30:00 +0000

Type Values Removed Values Added
First Time appeared Tp-link
Tp-link tapo C520ws V2
Vendors & Products Tp-link
Tp-link tapo C520ws V2

Sat, 06 Jun 2026 00:15:00 +0000

Type Values Removed Values Added
Description An authenticated format string vulnerability exists in the ONVIF Subscribe service in Tapo C520WS v2 due to improper handling of externally supplied parameters within formatting functions. An attacker may inject crafted format strings into event subscription requests or notification generation path to disrupt normal service execution. Successful exploitation may cause the event notification service to terminate unexpectedly, resulting in the loss of real-time alarm functionality and disruption of event notifications.
Title Authenticated Format String Vulnerability in ONVIF Subscribe Service on TP-Link Tapo C520WS
Weaknesses CWE-134
References
Metrics cvssV4_0

{'score': 6.8, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: TPLink

Published: 2026-06-05T23:52:36.290Z

Updated: 2026-06-08T13:17:15.157Z

Reserved: 2026-04-13T17:10:28.804Z

Link: CVE-2026-6242

cve-icon Vulnrichment

Updated: 2026-06-08T13:17:11.849Z

cve-icon NVD

Status : Deferred

Published: 2026-06-06T00:16:41.347

Modified: 2026-06-08T15:01:06.580

Link: CVE-2026-6242

cve-icon Redhat

No data.