Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pmj5-p8gw-hpgq

Опубликовано: 06 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 6.8

Описание

An authenticated format string vulnerability is present in the ONVIF AddScopes in Tapo C520WS v2, where user-controlled input is improperly passed to formatting functions without adequate sanitization. An attacker can inject format specifiers into ONVIF scope parameters to manipulate memory handling behavior.

Successful exploitation may cause the ONVIF management service to crash, resulting in DoS condition that impacts normal device operation.

An authenticated format string vulnerability is present in the ONVIF AddScopes in Tapo C520WS v2, where user-controlled input is improperly passed to formatting functions without adequate sanitization. An attacker can inject format specifiers into ONVIF scope parameters to manipulate memory handling behavior.

Successful exploitation may cause the ONVIF management service to crash, resulting in DoS condition that impacts normal device operation.

EPSS

Процентиль: 6%
0.00163
Низкий

6.8 Medium

CVSS4

Дефекты

CWE-134

Связанные уязвимости

nvd
2 месяца назад

An authenticated format string vulnerability is present in the ONVIF AddScopes in Tapo C520WS v2, where user-controlled input is improperly passed to formatting functions without adequate sanitization. An attacker can inject format specifiers into ONVIF scope parameters to manipulate memory handling behavior. Successful exploitation may cause the ONVIF management service to crash, resulting in DoS condition that impacts normal device operation.

EPSS

Процентиль: 6%
0.00163
Низкий

6.8 Medium

CVSS4

Дефекты

CWE-134