CVE-2026-0652

On TP-Link Tapo C260 v1, command injection vulnerability exists due to improper sanitization in certain POST parameters during configuration synchronization. An authenticated attacker can execute arbitrary system commands with high impact on confidentiality, integrity and availability. It may cause full device compromise.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:tp-link:tapo_c260_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:tapo_c260:1:*:*:*:*:*:*:*

History

13 Feb 2026, 20:45

Type Values Removed Values Added
CPE cpe:2.3:h:tp-link:tapo_c260:1:*:*:*:*:*:*:*
cpe:2.3:o:tp-link:tapo_c260_firmware:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8
References () https://www.tp-link.com/en/support/download/tapo-c260/v1/ - () https://www.tp-link.com/en/support/download/tapo-c260/v1/ - Product
References () https://www.tp-link.com/us/support/download/tapo-c260/v1/ - () https://www.tp-link.com/us/support/download/tapo-c260/v1/ - Product
References () https://www.tp-link.com/us/support/faq/4960/ - () https://www.tp-link.com/us/support/faq/4960/ - Vendor Advisory
First Time Tp-link
Tp-link tapo C260
Tp-link tapo C260 Firmware

10 Feb 2026, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-10 18:16

Updated : 2026-02-13 20:45


NVD link : CVE-2026-0652

Mitre link : CVE-2026-0652

CVE.ORG link : CVE-2026-0652


JSON object : View

Products Affected

tp-link

  • tapo_c260
  • tapo_c260_firmware
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')