Aller au contenu

Fiche vulnérabilité

CVE-2026-0653 : faille moyenne tp-link tapo c260 firmware (CVSS 6.5)

Description

On TP-Link Tapo C260 v1 and D235 v1, a guest‑level authenticated user can bypass intended access restrictions by sending crafted requests to a synchronization endpoint. This allows modification of protected device settings despite limited privileges. An attacker may change sensitive configuration parameters without authorization, resulting in unauthorized device state manipulation but not full code execution.

En bref

Sévérité
Moyenne (CVSS 6.5)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Exploitation active
Non signalée par la CISA
Publication
10 févr. 2026
Dernière mise à jour
17 juin 2026

Produits concernés

  • tp-link tapo c260 firmware

Références

Rechercher une autre vulnérabilité dans la base CVE