PT-2026-29849 · Tp Link Systems+1 · Tapo C520Ws V2.6+1
Published
2026-04-02
·
Updated
2026-04-29
·
CVE-2026-34121
CVSS v3.1
8.8
High
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
TP-Link Tapo C520WS version 2.6
Description
An authentication bypass exists in the HTTP handling of the DS configuration service. The issue stems from inconsistent parsing and authorization logic in JSON requests during authentication checks. An unauthenticated attacker can bypass authorization by appending an authentication-exempt action to a request that contains privileged DS do actions. This allows the unauthorized execution of restricted configuration actions, which may lead to the unauthorized modification of the device state.
Recommendations
Update TP-Link Tapo C520WS version 2.6 to the latest firmware version provided by the manufacturer.
Isolate management interfaces from untrusted networks.
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tapo C520Ws V2.6
Tapo C520Ws Firmware