HomeSecurityCritical vulnerabilities in TP-Link Tapo C520WS cameras

Critical vulnerabilities in TP-Link Tapo C520WS cameras

Serious security flaws have been identified in TP-Link Tapo C520WS smart cameras, raising concerns about the reliability of IoT devices used for surveillance. If exploited, the vulnerabilities could allow attackers on the same network to cause a shutdown, crash the device , or even entirely authentication mechanisms.

TP-Link Tapo C520WS cameras

TP-Link has already released an urgent firmware update, urging users to install it immediately. This is particularly critical, as a successful attack could create surveillance blind spots, undermining the security of homes and businesses.

See also: Hackers exploit CVE-2025-55182 to compromise 766 Next.js Hosts

The most dangerous vulnerability and authentication bypass

Among the findings, the vulnerability CVE-2026-34121 with a high severity rating. The problem is located in the way the device handles HTTP requests and JSON data, allowing an unauthorized user to bypass authentication checks.

In practice, an attacker can modify requests by adding specific parameters, gaining access to functions that normally require credentials. This means that basic camera settings can be changed without the owner being aware of it.

This particular vulnerability highlights a perennial problem in the IoT space: the inadequate implementation of authorization mechanisms, which is often sacrificed for reasons of convenience or cost.

DoS and buffer overflow attacks

In addition to bypassing authentication, researchers identified multiple buffer overflow vulnerabilities, which can lead to a complete device crash. These attacks exploit flaws in input control, allowing specially crafted requests to be sent that cause system instability.

See also: Progress ShareFile: Combination of vulnerabilities allows RCE attacks

Critical vulnerabilities in TP-Link Tapo C520WS cameras

Vulnerabilities CVE-2026-34118, CVE-2026-34119 and CVE-2026-34120 are related to heap-based overflow vulnerabilities, while CVE-2026-34122 concerns stack-based overflow. In addition, vulnerability CVE-2026-34124.

The result of all this can be a Denial of Service (DoS) attack, where the camera stops working or restarts constantly, rendering it essentially useless at the moment it is needed most.

TP-Link: Which devices are affected and what users should do

The issues affect Tapo C520WS v2.6 series cameras using older firmware versions (before 1.2.4 Build 260326 Rel. 24666n). TP-Link has already released a patch that addresses the security vulnerabilities.

Users are urged to check for updates immediately either through the official app or through the support pages. Failure to install patches leaves devices exposed to attacks that can lead to both loss of functionality and privacy breaches.

The broader risks of IoT devices

This incident highlights a broader challenge: the security of connected devices. Security cameras, routers and other IoT devices are often weak links, as they combine constant internet connectivity with limited protection mechanisms.

See also: Cisco SSM On-Prem: Critical vulnerability threatens enterprise networks

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Critical vulnerabilities in TP-Link Tapo C520WS cameras

In cases of DoS attacks, disabling a camera can facilitate physical breaches, while in more sophisticated scenarios attackers could gain access to live video or sensitive data.

The importance of updates and proper management

The TP-Link Tapo C520WS case highlights how critical it is for users to keep their devices up to date. Unlike other categories of software, IoT devices often go years without updates, increasing the risk of exploitation.

Installing firmware updates early, using strong passwords, and isolating such devices on separate networks are key protection measures. As the IoT ecosystem continues to grow, security cannot be taken for granted, but requires constant vigilance from manufacturers and users.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS