HarborGuard / CVE
Back to search
HIGHCVE-2026-0652Published Modified CNA TPLink

CVE-2026-0652: Remote Code Execution on TP-Link Tapo C260 by Guest User

On TP-Link Tapo C260 v1, command injection vulnerability exists due to improper sanitization in certain POST parameters during configuration synchronization. An authenticated attacker can execute arbitrary system commands with high impact on confidentiality, integrity and availability. It may cause full device compromise.

Metrics

CVSS v4.0
8.7
Severity
HIGH
Fixed in
1.1.9 Build 251226 Rel.55870n
Affected Products
1

Fix available

1.1.9 Build 251226 Rel.55870n
Affected packages
  • TP-Link Systems Inc. / Tapo C260 v1
    < 1.1.9 Build 251226 Rel.55870n (from 0)
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L
CVE-2026-0652: Remote Code Execution on TP-Link Tapo C260 by Guest User | HarborGuard CVE