PT-2026-7323 · Tp Link · Tapo C260
Spaceraccoon
·
Published
2026-02-10
·
Updated
2026-03-10
·
CVE-2026-0652
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
TP-Link Tapo C260 version 1
Description
A command injection issue exists in the TP-Link Tapo C260 v1 due to insufficient input validation of certain POST parameters during configuration synchronization. A successful exploit by an authenticated attacker could allow for the execution of arbitrary system commands, potentially leading to a complete compromise of the device, impacting confidentiality, integrity, and availability. The vulnerability allows an attacker to execute arbitrary code through specific POST request parameters.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tapo C260