CVE-2026-6241
Last modified
CVE-2026-6241 is a medium-severity vulnerability rated 6.8/10 on the CVSS scale. An authenticated format string vulnerability is present in the ONVIF AddScopes in Tapo C520WS v2, where user-controlled input is improperly passed to formatting functions without adequate sanitization. An attacker can inject format specifiers into ONVIF scope parameters to manipulate memory handling behavior. Successful exploitation may cause the ONVIF management service to crash, resulting in DoS condition that impacts normal device operation.. EPSS estimates a 0.16% chance of exploitation in the next 30 days.
Description
An authenticated format string vulnerability is present in the ONVIF AddScopes in Tapo C520WS v2, where user-controlled input is improperly passed to formatting functions without adequate sanitization. An attacker can inject format specifiers into ONVIF scope parameters to manipulate memory handling behavior. Successful exploitation may cause the ONVIF management service to crash, resulting in DoS condition that impacts normal device operation.
Metrics
CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-6241?
How severe is CVE-2026-6241?
How do I fix CVE-2026-6241?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-6239A stack‑based buffer overflow vulnerability exists in Tapo C…6.8
- CVE-2026-62390Improper Neutralization of Special Elements used in an SQL C…9.8
- CVE-2026-62391The security fix for CVE-2025-66518 is incomplete. Any clien…8.1
- CVE-2026-62392Improper Neutralization of Special Elements used in an OS Co…9.8
- CVE-2026-62393Improper Handling of Insufficient Permissions or Privileges …4.3
- CVE-2026-6240A stack-based buffer overflow vulnerability exists in Tapo C…6.8
- CVE-2026-62414Joomla Extension - joomlack.fr - Improper access control in …9.1
- CVE-2026-62415Joomla Extension - joomdonation.com - Insecure default confi…9.1
- CVE-2026-62416Network Scanner Tool and Network Scanner Tool Lite provided …6.9
- CVE-2026-62418Low-privileged authenticated Server-Side Request Forgery (SS…8.1
- CVE-2026-6242An authenticated format string vulnerability exists in the O…6.8
- CVE-2026-62420An authorization bypass vulnerability in LXD allows an authe…9.9
Are you affected by CVE-2026-6241?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
