Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-6241

Опубликовано: 06 июн. 2026
Источник: nvd
EPSS Низкий

Описание

An authenticated format string vulnerability is present in the ONVIF AddScopes in Tapo C520WS v2, where user-controlled input is improperly passed to formatting functions without adequate sanitization. An attacker can inject format specifiers into ONVIF scope parameters to manipulate memory handling behavior.

Successful exploitation may cause the ONVIF management service to crash, resulting in DoS condition that impacts normal device operation.

EPSS

Процентиль: 6%
0.00163
Низкий

Дефекты

CWE-134

Связанные уязвимости

github
2 месяца назад

An authenticated format string vulnerability is present in the ONVIF AddScopes in Tapo C520WS v2, where user-controlled input is improperly passed to formatting functions without adequate sanitization. An attacker can inject format specifiers into ONVIF scope parameters to manipulate memory handling behavior. Successful exploitation may cause the ONVIF management service to crash, resulting in DoS condition that impacts normal device operation.

EPSS

Процентиль: 6%
0.00163
Низкий

Дефекты

CWE-134