On TP-Link Tapo C260 v1, command injection vulnerability exists due to improper sanitization in certain POST parameters during configuration synchronization. An authenticated attacker can execute arbitrary system commands with high impact on confidentiality, integrity and availability. It may cause full device compromise.
References
| Link | Resource |
|---|---|
| https://www.tp-link.com/en/support/download/tapo-c260/v1/ | Product |
| https://www.tp-link.com/us/support/download/tapo-c260/v1/ | Product |
| https://www.tp-link.com/us/support/faq/4960/ | Vendor Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
History
13 Feb 2026, 20:45
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:h:tp-link:tapo_c260:1:*:*:*:*:*:*:* cpe:2.3:o:tp-link:tapo_c260_firmware:*:*:*:*:*:*:*:* |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
| References | () https://www.tp-link.com/en/support/download/tapo-c260/v1/ - Product | |
| References | () https://www.tp-link.com/us/support/download/tapo-c260/v1/ - Product | |
| References | () https://www.tp-link.com/us/support/faq/4960/ - Vendor Advisory | |
| First Time |
Tp-link
Tp-link tapo C260 Tp-link tapo C260 Firmware |
10 Feb 2026, 18:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-10 18:16
Updated : 2026-02-13 20:45
NVD link : CVE-2026-0652
Mitre link : CVE-2026-0652
CVE.ORG link : CVE-2026-0652
JSON object : View
Products Affected
tp-link
- tapo_c260
- tapo_c260_firmware
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
