A Leader in the 2026 Gartner® Magic Quadrant™ for Endpoint Protection. Six years running.Six years. Gartner® Magic Quadrant™ Leader.Find Out Why
Experiencing a Breach?Blog
Get StartedContact Us
SentinelOne
  • Platform
    Platform Overview
    • Singularity Platform
      Welcome to Integrated Enterprise Security
    • AI for Security
      Leading the Way in AI-Powered Security Solutions
    • Securing AI
      Accelerate AI Adoption with Secure AI Tools, Apps, and Agents.
    • How It Works
      The Singularity XDR Difference
    • Singularity Marketplace
      One-Click Integrations to Unlock the Power of XDR
    • Pricing & Packaging
      Comparisons and Guidance at a Glance
    Data & AI
    • Purple AI
      Accelerate SecOps with Generative AI
    • Singularity Hyperautomation
      Easily Automate Security Processes
    • AI-SIEM
      The AI SIEM for the Autonomous SOC
    • AI Data Pipelines
      Security Data Pipeline for AI SIEM and Data Optimization
    • Singularity Data Lake
      AI-Powered, Unified Data Lake
    • Singularity Data Lake for Log Analytics
      Seamlessly Ingest Data from On-Prem, Cloud or Hybrid Environments
    Endpoint Security
    • Singularity Endpoint
      Autonomous Prevention, Detection, and Response
    • Singularity XDR
      Native & Open Protection, Detection, and Response
    • Singularity RemoteOps Forensics
      Orchestrate Forensics at Scale
    • Singularity Threat Intelligence
      Comprehensive Adversary Intelligence
    • Singularity Vulnerability Management
      Application & OS Vulnerability Management
    • Singularity Identity
      Identity Threat Detection and Response
    Cloud Security
    • Singularity Cloud Security
      Block Attacks with an AI-Powered CNAPP
    • Singularity Cloud Native Security
      Secure Cloud and Development Resources
    • Singularity Cloud Workload Security
      Real-Time Cloud Workload Protection Platform
    • Singularity Cloud Data Security
      AI-Powered Threat Detection for Cloud Storage
    • Singularity Cloud Security Posture Management
      Detect and Remediate Cloud Misconfigurations
    Securing AI
    • Prompt Security
      Secure AI Tools Across Your Enterprise
  • Why SentinelOne?
    Why SentinelOne?
    • Why SentinelOne?
      Cybersecurity Built for What’s Next
    • Our Customers
      Trusted by the World’s Leading Enterprises
    • Industry Recognition
      Tested and Proven by the Experts
    • About Us
      The Industry Leader in Autonomous Cybersecurity
    Compare SentinelOne
    • Arctic Wolf
    • Broadcom
    • CrowdStrike
    • Cybereason
    • Microsoft
    • Palo Alto Networks
    • Sophos
    • Splunk
    • Trellix
    • Trend Micro
    • Wiz
    Verticals
    • Energy
    • Federal Government
    • Finance
    • Healthcare
    • Higher Education
    • K-12 Education
    • Manufacturing
    • Retail
    • State and Local Government
  • Services
    Managed Services
    • Managed Services Overview
      Wayfinder Threat Detection & Response
    • Threat Hunting
      World-Class Expertise and Threat Intelligence
    • Managed Detection & Response
      24/7/365 Expert MDR Across Your Entire Environment
    • Incident Readiness & Response
      DFIR, Breach Readiness, & Compromise Assessments
    Support, Deployment, & Health
    • Technical Account Management
      Customer Success with Personalized Service
    • SentinelOne GO
      Guided Onboarding & Deployment Advisory
    • SentinelOne University
      Live and On-Demand Training
    • Services Overview
      Comprehensive Solutions for Seamless Security Operations
    • SentinelOne Community
      Community Login
  • Partners
    Our Network
    • MSSP Partners
      Succeed Faster with SentinelOne
    • Singularity Marketplace
      Extend the Power of S1 Technology
    • Cyber Risk Partners
      Enlist Pro Response and Advisory Teams
    • Technology Alliances
      Integrated, Enterprise-Scale Solutions
    • SentinelOne for AWS
      Hosted in AWS Regions Around the World
    • Channel Partners
      Deliver the Right Solutions, Together
    • SentinelOne for Google Cloud
      Unified, Autonomous Security Giving Defenders the Advantage at Global Scale
    • Partner Locator
      Your Go-to Source for Our Top Partners in Your Region
    Partner Portal→
  • Resources
    Resource Center
    • Case Studies
    • Data Sheets
    • eBooks
    • Reports
    • Videos
    • Webinars
    • Whitepapers
    • Events
    View All Resources→
    Blog
    • Feature Spotlight
    • For CISO/CIO
    • From the Front Lines
    • Identity
    • Cloud
    • macOS
    • SentinelOne Blog
    Blog→
    Tech Resources
    • SentinelLABS
    • Ransomware Anthology
    • Cybersecurity 101
  • About
    About SentinelOne
    • About SentinelOne
      The Industry Leader in Cybersecurity
    • Investor Relations
      Financial Information & Events
    • SentinelLABS
      Threat Research for the Modern Threat Hunter
    • Careers
      The Latest Job Opportunities
    • Press & News
      Company Announcements
    • Cybersecurity Blog
      The Latest Cybersecurity Threats, News, & More
    • FAQ
      Get Answers to Our Most Frequently Asked Questions
    • DataSet
      The Live Data Platform
    • S Foundation
      Securing a Safer Future for All
    • S Ventures
      Investing in the Next Generation of Security, Data and AI
  • Pricing
Get StartedContact Us
CVE Vulnerability Database
Vulnerability Database/CVE-2026-6241

CVE-2026-6241: Tapo C520WS Format String DoS Vulnerability

CVE-2026-6241 is a format string denial of service vulnerability in Tapo C520WS v2 ONVIF AddScopes that allows authenticated attackers to crash the management service. This post covers technical details, affected versions, and mitigation.

Published: June 11, 2026

CVE-2026-6241 Overview

CVE-2026-6241 is an authenticated format string vulnerability [CWE-134] affecting the ONVIF AddScopes operation in the TP-Link Tapo C520WS v2 network camera. The flaw stems from user-controlled input being passed to formatting functions without adequate sanitization. An authenticated attacker on an adjacent network can inject format specifiers into ONVIF scope parameters to manipulate memory handling behavior. Successful exploitation crashes the ONVIF management service, producing a denial-of-service (DoS) condition that disrupts normal camera operation.

Critical Impact

An authenticated adjacent-network attacker can crash the ONVIF management service on the Tapo C520WS v2, disrupting video surveillance and remote management functionality.

Affected Products

  • TP-Link Tapo C520WS v2 network camera
  • ONVIF management service on affected firmware versions
  • Deployments exposing ONVIF endpoints on local or adjacent networks

Discovery Timeline

  • 2026-06-06 - CVE-2026-6241 published to NVD
  • 2026-06-08 - Last updated in NVD database

Technical Details for CVE-2026-6241

Vulnerability Analysis

The vulnerability resides in the ONVIF (Open Network Video Interface Forum) AddScopes operation, a SOAP-based method used to add scope parameters that describe device capabilities and metadata. The Tapo C520WS v2 firmware forwards attacker-supplied scope strings into C-style formatting functions such as printf, sprintf, or logging wrappers without first stripping or escaping format conversion specifiers. When the resulting string contains tokens like %s, %x, or %n, the formatting function interprets them as directives and reads or writes memory locations that were never intended to be exposed to attacker control.

In this implementation, the impact is limited to memory corruption that crashes the ONVIF service, producing a denial-of-service condition. Because authentication is required and the vulnerability is reachable only from an adjacent network, mass exploitation is unlikely. However, in shared corporate or multi-tenant environments where ONVIF credentials are widely distributed, abuse remains practical.

Root Cause

The root cause is improper handling of externally-influenced input within a format string [CWE-134]. The ONVIF service treats the scope value provided by the SOAP client as a format string rather than as data, violating the standard practice of using a fixed format specifier such as "%s" paired with the untrusted argument.

Attack Vector

An attacker authenticates to the ONVIF endpoint exposed by the Tapo C520WS v2 over the local or adjacent network. The attacker then issues an AddScopes SOAP request whose Scopes element contains crafted format specifiers. When the camera firmware passes the value to its internal logging or formatting routine, the specifiers trigger invalid memory accesses, terminating the ONVIF service and breaking remote video management until the device or service restarts.

No verified public proof-of-concept code is available. Refer to the TP-Link FAQ on Tapo C520WS for vendor guidance.

Detection Methods for CVE-2026-6241

Indicators of Compromise

  • Repeated ONVIF AddScopes SOAP requests containing format specifiers such as %s, %x, %p, or %n in the Scopes element.
  • Unexpected restarts or crash logs from the ONVIF management service on Tapo C520WS v2 devices.
  • Loss of ONVIF discovery, PTZ, or streaming functionality while the underlying RTSP stream remains active.

Detection Strategies

  • Inspect SOAP traffic to TCP ports used by ONVIF (commonly 2020, 8080, or 80) for AddScopes requests containing % conversion characters in scope URIs.
  • Correlate authentication events on the camera with subsequent ONVIF service crashes to identify abusive accounts.
  • Baseline the rate of AddScopes invocations; legitimate use is rare and configuration-driven, so spikes warrant investigation.

Monitoring Recommendations

  • Forward camera syslog and ONVIF service logs to a centralized SIEM and alert on repeated service termination events.
  • Monitor network segments hosting IP cameras for unauthorized hosts initiating ONVIF SOAP sessions.
  • Track firmware versions across the IoT inventory to confirm patched builds are deployed.

How to Mitigate CVE-2026-6241

Immediate Actions Required

  • Apply the latest firmware for the Tapo C520WS v2 as listed in the TP-Link Firmware Release Notes.
  • Rotate ONVIF account credentials and remove unused accounts on affected cameras.
  • Restrict ONVIF access to a dedicated management VLAN that excludes general user devices.

Patch Information

TP-Link addresses the issue in firmware updates published on the Tapo C520WS v2 product page. Review the TP-Link Firmware Release Notes for the fixed version applicable to your regional firmware track, and validate the running build using the camera's web management interface or the Tapo mobile application.

Workarounds

  • Disable ONVIF on cameras that do not require third-party Video Management System integration.
  • Apply ACLs or firewall rules to permit ONVIF SOAP traffic only from trusted management hosts.
  • Use strong, unique ONVIF credentials and disable shared service accounts to limit which authenticated users can reach AddScopes.
bash
# Example: restrict ONVIF access to a single management host using iptables on an upstream gateway
iptables -A FORWARD -p tcp -s 192.0.2.10 -d 192.0.2.50 --dport 2020 -j ACCEPT
iptables -A FORWARD -p tcp -d 192.0.2.50 --dport 2020 -j DROP

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

  • Vulnerability Details
  • TypeDOS

  • Vendor/TechTapo

  • SeverityMEDIUM

  • CVSS Score6.8

  • EPSS Probability0.02%

  • Known ExploitedNo
  • CVSS Vector
  • CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Impact Assessment
  • ConfidentialityLow
  • IntegrityNone
  • AvailabilityHigh
  • CWE References
  • CWE-134
  • Technical References
  • TP-Link Firmware Release Notes

  • TP-Link Firmware Release Notes

  • TP-Link FAQ on Tapo C520WS
  • Related CVEs
  • CVE-2026-6240: Tapo C520WS Buffer Overflow DoS Vulnerability

  • CVE-2026-6242: Tapo C520WS Format String DoS Vulnerability

  • CVE-2026-6239: Tapo C520WS Buffer Overflow DoS Vulnerability

  • CVE-2026-1315: Tapo Camera DoS Vulnerability
Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.

Try SentinelOne
  • Get Started
  • Get a Demo
  • Product Tour
  • Why SentinelOne
  • Pricing & Packaging
  • FAQ
  • Contact
  • Contact Us
  • Customer Support
  • SentinelOne Status
  • Language
  • Platform
  • Singularity Platform
  • Singularity Endpoint
  • Singularity Cloud
  • Singularity AI-SIEM
  • Singularity Identity
  • Singularity Marketplace
  • Purple AI
  • Services
  • Wayfinder TDR
  • SentinelOne GO
  • Technical Account Management
  • Support Services
  • Verticals
  • Energy
  • Federal Government
  • Finance
  • Healthcare
  • Higher Education
  • K-12 Education
  • Manufacturing
  • Retail
  • State and Local Government
  • Cybersecurity for SMB
  • Resources
  • Blog
  • Labs
  • Case Studies
  • Videos
  • Product Tours
  • Events
  • Cybersecurity 101
  • eBooks
  • Webinars
  • Whitepapers
  • Press
  • News
  • Ransomware Anthology
  • Company
  • About Us
  • Our Customers
  • Careers
  • Partners
  • Legal & Compliance
  • Security & Compliance
  • Investor Relations
  • S Foundation
  • S Ventures

©2026 SentinelOne, All Rights Reserved.

Privacy Notice Terms of Use

English