CVE-2026-0652
Remote Code Execution on TP-Link Tapo C260 by Guest User
8.7
HIGH
CVSS 4.0
EPSS 22.4% · 98th pctCWE-78
2026-02-10•Updated 2026-02-11
Description
On TP-Link Tapo C260 v1, command injection vulnerability exists due to improper sanitization in certain POST parameters during configuration synchronization. An authenticated attacker can execute arbitrary system commands with high impact on confidentiality, integrity and availability. It may cause full device compromise.
Severity
CVSS 4.0 · CNA8.7 HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:LSSVC · CISA-ADP
Exploitationnone
Automatableno
Technical impacttotal
Affected Products
| Vendor | Product | Affected versions |
|---|---|---|
| TP-Link Systems Inc. | Tapo C260 v1 | 0 to <1.1.9 Build 251226 Rel.55870n |
References
3 LinksRecord Details
Published
2026-02-10
Last updated
2026-02-11
Assigner (CNA)
TPLink
Credited to
spaceraccoon
More from TP-Link Systems Inc.
Related Tool Categories
Tool categories that test for or protect against this vulnerability class.
CWE-78 · OS Command Injection
CVE record data © The MITRE Corporation, used under the CVE Terms of Use. Exploited-in-the-wild data from the CISA Known Exploited Vulnerabilities catalog (CC0). Exploit prediction scores by FIRST EPSS (first.org/epss). This site is not endorsed or certified by MITRE, NVD, CISA, or FIRST.