CVE-2026-0652
massAuthenticated Command Injection in TP-Link Tapo C260 Camera Firmware
CVE-2026-0652 is a command injection flaw (CWE-78) in the firmware of TP-Link Tapo C260 cameras, specifically hardware version v1, caused by improper sanitization of certain POST parameters used during configuration synchronization. An attacker who already holds valid (low-privilege) credentials for the camera can submit crafted values in these parameters, causing arbitrary operating-system commands to be executed on the device. The injected commands run on the camera's underlying system, so the impact on confidentiality, integrity and availability is high and full device compromise is possible. Only users operating a TP-Link Tapo C260 v1 camera are affected. The flaw is not yet listed in CISA's KEV catalog and no public proof-of-concept is known, but its EPSS score of 21.9% (98th percentile) indicates an elevated probability of exploitation within the next 30 days.
What to do: Monitor the Tapo app and TP-Link's support/download site for a patched firmware release for the Tapo C260 (v1) and apply it as soon as it is published, since no fixed version is identified yet. Until then, restrict and strengthen credentials for the camera (strong, unique passwords), review which accounts have access, and disable remote/cloud access if it is not required. Ensure the camera is not directly reachable from the internet and sits behind a firewall with only necessary outbound connectivity.
| TP-Link Tapo C260 camera firmware (hardware version v1) | Hardware version v1; affected and fixed firmware version ranges are not specified in the available data |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
On TP-Link Tapo C260 v1, command injection vulnerability exists due to improper sanitization in certain POST parameters during configuration synchronization. An authenticated attacker can execute arbitrary system commands with high impact on confidentiality, integrity and availability. It may cause full device compromise.
- Vendors
- tp-link
- Products
- tapo c260 firmware
- Weakness
- CWE-78
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.