HarborGuard / CVE
Back to search
HIGHCVE-2026-34121Published Modified CNA TPLink

CVE-2026-34121: Authentication Bypass in DS Configuration Service via HTTP Request Parsing Differential of TP-Link Tapo C520WS

An authentication bypass vulnerability within the HTTP handling of the DS configuration service in TP-Link Tapo C520WS v2.6 was identified, due to inconsistent parsing and authorization logic in JSON requests during authentication check. An unauthenticated attacker can append an authentication-exempt action to a request containing privileged DS do actions, bypassing authorization checks. Successful exploitation allows unauthenticated execution of restricted configuration actions, which may result in unauthorized modification of device state.

Metrics

CVSS v4.0
8.7
Severity
HIGH
Fixed in
1.2.4 Build 260326 Rel.24666n
Affected Products
1

Fix available

1.2.4 Build 260326 Rel.24666n
Affected packages
  • TP-Link Systems Inc. / Tapo C520WS v2.6
    < 1.2.4 Build 260326 Rel.24666n (from 0)
CVSS Vector
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N