{"id":11830,"date":"2026-04-03T10:04:15","date_gmt":"2026-04-03T10:04:15","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/04\/03\/multiple-tp-link-vulnerabilities-let-attackers-trigger-dos-and-crash-routers\/"},"modified":"2026-04-03T10:04:15","modified_gmt":"2026-04-03T10:04:15","slug":"multiple-tp-link-vulnerabilities-let-attackers-trigger-dos-and-crash-routers","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/04\/03\/multiple-tp-link-vulnerabilities-let-attackers-trigger-dos-and-crash-routers\/","title":{"rendered":"Multiple TP-Link Vulnerabilities Let Attackers Trigger DoS and Crash Routers"},"content":{"rendered":"<p>    Multiple TP-Link Vulnerabilities Let Attackers Trigger DoS and Crash Routers<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Multiple high-severity vulnerabilities exist in TP-Link\u2019s Tapo C520WS smart security cameras. If exploited, these vulnerabilities may allow adjacent attackers to trigger Denial-of-Service (DoS) conditions, crash the device, or completely bypass authentication.<\/p>\n<p>TP-Link has released urgent firmware updates to address these critical security gaps. When a security camera or connected router goes offline due to a DoS attack, it <a href=\"https:\/\/cybersecuritynews.com\/linux-io_uring-security-blind-spot\/\" target=\"_blank\" rel=\"noreferrer noopener\">creates an immediate physical security blind spot<\/a>.<\/p>\n<p>This makes patching these vulnerabilities especially critical for users relying on the Tapo C520WS for active surveillance and property monitoring.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-multiple-tp-link-vulnerabilities\"><strong>Multiple TP-Link Vulnerabilities<\/strong><\/h2>\n<p>The most severe of the discovered flaws is CVE-2026-34121, which carries a CVSS v4.0 score of 8.7. This vulnerability involves an authentication bypass within the HTTP handling of the <a href=\"https:\/\/cybersecuritynews.com\/unifi-protect-camera-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">camera\u2019s DS configuration service<\/a>.<\/p>\n<p>Because of inconsistent parsing and authorization logic in JSON requests, an unauthenticated attacker on the same network segment can easily bypass security checks.<\/p>\n<p>By appending an exempt action to a privileged request, hackers can execute restricted configuration changes and alter the device\u2019s state without ever needing valid login credentials.<\/p>\n<p>Alongside the authentication bypass, researchers identified several <a href=\"https:\/\/cybersecuritynews.com\/chrome-buffer-overflow-vulnerabilities\/\" target=\"_blank\" rel=\"noreferrer noopener\">buffer overflow vulnerabilities<\/a> that can be leveraged to crash the device or force a sudden reboot, resulting in a complete Denial-of-Service.<\/p>\n<p><strong>CVE-2026-34118, CVE-2026-34119, CVE-2026-34120:<\/strong> These heap-based overflow flaws (CVSS 7.1) stem from poor boundary validation in HTTP and streaming inputs.<\/p>\n<p>Attackers can send crafted payloads to cause <a href=\"https:\/\/cybersecuritynews.com\/most-exploited-vulnerabilities-of-2025\/\">memory corruption during HTTP POST parsing,<\/a> segmented request appending, or asynchronous video stream processing.<\/p>\n<p><strong>CVE-2026-34122:<\/strong> Found in the DS configuration service, this stack-based overflow (CVSS 7.1) allows attackers to supply excessively long configuration parameters to crash the service.<\/p>\n<p><strong>CVE-2026-34124:<\/strong> Also rated CVSS 7.1, this path-expansion overflow occurs in the HTTP request parsing logic.<\/p>\n<p>The system checks raw request lengths but fails to account for size increases <a href=\"https:\/\/cybersecuritynews.com\/dnn-vulnerability-let-attackers-steal-ntlm-credentials\/\" target=\"_blank\" rel=\"noreferrer noopener\">during path normalization,<\/a> allowing adjacent attackers to trigger a system interruption.<\/p>\n<p>These vulnerabilities specifically affect the Tapo C520WS v2.6 running firmware versions before 1.2.4 Build 260326 Rel. 24666n.<\/p>\n<p>Users are strongly urged to apply the latest firmware patches immediately. Leaving devices unpatched exposes them <span style=\"box-sizing: border-box; margin: 0px; padding: 0px;\">to<a href=\"https:\/\/cybersecuritynews.com\/fortigate-firewalls-hacked\/\" target=\"_blank\" rel=\"noopener\">\u00a0unauthorized<\/a><\/span><a href=\"https:\/\/cybersecuritynews.com\/fortigate-firewalls-hacked\/\" target=\"_blank\" rel=\"noreferrer noopener\"> configuration changes and persistent crashing.<\/a><\/p>\n<p>You can download the <a href=\"https:\/\/www.tp-link.com\/us\/support\/faq\/5047\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">updated firmware directly from TP-Link\u2019s official support pages<\/a> or check for updates in the companion mobile application. TP-Link notes that they cannot bear responsibility for security consequences if these provided updates are ignored.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/tp-link-vulnerabilities-trigger-dos\/\">Multiple TP-Link Vulnerabilities Let Attackers Trigger DoS and Crash Routers<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Abinaya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/tp-link-vulnerabilities-trigger-dos\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Multiple TP-Link Vulnerabilities Let Attackers Trigger DoS and Crash Routers Multiple high-severity vulnerabilities exist in TP-Link\u2019s Tapo C520WS smart security cameras. If exploited, these vulnerabilities may allow adjacent attackers to trigger Denial-of-Service (DoS) conditions, crash the device, or completely bypass authentication. TP-Link has released urgent firmware updates to address these critical security gaps. When a [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,648],"tags":[130],"class_list":["post-11830","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-vulnerability-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/11830"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=11830"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/11830\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=11830"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=11830"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=11830"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}