PT-2026-29849 · Tp Link Systems+1 · Tapo C520Ws V2.6+1

Published

2026-04-02

·

Updated

2026-04-29

·

CVE-2026-34121

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TP-Link Tapo C520WS version 2.6
Description An authentication bypass exists in the HTTP handling of the DS configuration service. The issue stems from inconsistent parsing and authorization logic in JSON requests during authentication checks. An unauthenticated attacker can bypass authorization by appending an authentication-exempt action to a request that contains privileged DS do actions. This allows the unauthorized execution of restricted configuration actions, which may lead to the unauthorized modification of the device state.
Recommendations Update TP-Link Tapo C520WS version 2.6 to the latest firmware version provided by the manufacturer. Isolate management interfaces from untrusted networks.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-34121

Affected Products

Tapo C520Ws V2.6
Tapo C520Ws Firmware