Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Authenticated Format String Vulnerability in ONVIF AddScopes Method on TP-Link Tapo C520WS
Vulnerability Description
An authenticated format string vulnerability is present in the ONVIF AddScopes in Tapo C520WS v2, where user-controlled input is improperly passed to formatting functions without adequate sanitization. An attacker can inject format specifiers into ONVIF scope parameters to manipulate memory handling behavior. Successful exploitation may cause the ONVIF management service to crash, resulting in DoS condition that impacts normal device operation.
CVSS Information
CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Vulnerability Type
使用外部控制的格式字符串
Vulnerability Title
TP-Link Tapo C520WS 安全漏洞
Vulnerability Description
TP-Link Tapo C520WS是中国普联(TP-Link)公司的一个WiFi摄像头。 TP-Link Tapo C520WS v2版本存在安全漏洞,该漏洞源于ONVIF AddScopes中格式字符串漏洞,用户控制的输入未充分清理即传递给格式化函数,可能导致经过身份验证的攻击者注入格式说明符,造成拒绝服务。
CVSS Information
N/A
Vulnerability Type
N/A