> CVE-2026-34124: TP-Link HTTP GET stack buffer overflow
[DATE: 28/04/2026 00:00]
[LANGUAGE: EN]
An attacker sending a malformed HTTP POST request over LAN to a TP-Link Smart camera device can trigger the vulnerability described here.
This report describes a stack buffer overflow, which leads to denial of service and may potentially lead to remote code execution.
The vulnerability we are disclosing in this advisory affected a wide range of TP-Link devices, including TAPO Smart Cameras. A TP-Link Security Advisory released in April 2026 contains this vulnerability as CVE-2026-34124.
Vulnerability Details We identified a stack buffer overflow vulnerability in the way te HTTP server of TAPO devices handles GET requests.
http_parser() { path = .