ZeroHour

CVE-2026-0652

mass

Authenticated Command Injection in TP-Link Tapo C260 Camera Firmware

CVSS 4.0
8.7 high
EPSS
22%p98
Published
()
Modified
AI analysis

CVE-2026-0652 is a command injection flaw (CWE-78) in the firmware of TP-Link Tapo C260 cameras, specifically hardware version v1, caused by improper sanitization of certain POST parameters used during configuration synchronization. An attacker who already holds valid (low-privilege) credentials for the camera can submit crafted values in these parameters, causing arbitrary operating-system commands to be executed on the device. The injected commands run on the camera's underlying system, so the impact on confidentiality, integrity and availability is high and full device compromise is possible. Only users operating a TP-Link Tapo C260 v1 camera are affected. The flaw is not yet listed in CISA's KEV catalog and no public proof-of-concept is known, but its EPSS score of 21.9% (98th percentile) indicates an elevated probability of exploitation within the next 30 days.

What to do: Monitor the Tapo app and TP-Link's support/download site for a patched firmware release for the Tapo C260 (v1) and apply it as soon as it is published, since no fixed version is identified yet. Until then, restrict and strengthen credentials for the camera (strong, unique passwords), review which accounts have access, and disable remote/cloud access if it is not required. Ensure the camera is not directly reachable from the internet and sits behind a firewall with only necessary outbound connectivity.

Affected
TP-Link Tapo C260 camera firmware (hardware version v1)Hardware version v1; affected and fixed firmware version ranges are not specified in the available data
Estimated exposure
masslikely on the order of hundreds of thousands to millions of consumer installs (single mainstream camera model, v1 hardware) — The Tapo C260 is a mass-market consumer Wi-Fi camera sold globally through retail channels, so the affected v1 installed base is plausibly in the hundreds of thousands to millions, although TP-Link does not publish per-model install counts…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

On TP-Link Tapo C260 v1, command injection vulnerability exists due to improper sanitization in certain POST parameters during configuration synchronization. An authenticated attacker can execute arbitrary system commands with high impact on confidentiality, integrity and availability. It may cause full device compromise.

Vendors
tp-link
Products
tapo c260 firmware
Weakness
CWE-78
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.