CVE-2026-0653: CWE-284 Improper Access Control in TP-Link Systems Inc. Tapo C260 v1
On TP-Link Tapo C260 v1 and D235 v1, a guest‑level authenticated user can bypass intended access restrictions by sending crafted requests to a synchronization endpoint. This allows modification of protected device settings despite limited privileges. An attacker may change sensitive configuration parameters without authorization, resulting in unauthorized device state manipulation but not full code execution.
AI Analysis
Technical Summary
This vulnerability (CWE-284) affects TP-Link Tapo C260 v1 and D235 v1 devices, where a guest-level authenticated user can bypass intended access controls by exploiting a synchronization endpoint. The attacker can modify protected device settings despite limited privileges, leading to unauthorized device state manipulation. The vulnerability does not allow full code execution. The CVSS 4.0 score is 7.2, indicating high severity, with network attack vector, low attack complexity, no user interaction, and partial confidentiality and integrity impact but high availability and authorization impact.
Potential Impact
An attacker with guest-level authentication can change sensitive device configuration parameters without proper authorization. This unauthorized modification can affect device behavior and availability but does not allow execution of arbitrary code or full system compromise.
Mitigation Recommendations
No patch or official fix information is currently available. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is provided, restrict guest-level access and monitor device configurations for unauthorized changes.
CVE-2026-0653: CWE-284 Improper Access Control in TP-Link Systems Inc. Tapo C260 v1
Description
On TP-Link Tapo C260 v1 and D235 v1, a guest‑level authenticated user can bypass intended access restrictions by sending crafted requests to a synchronization endpoint. This allows modification of protected device settings despite limited privileges. An attacker may change sensitive configuration parameters without authorization, resulting in unauthorized device state manipulation but not full code execution.
CVSS v4.0
Score 7.2high
Affected software
TP-Link Systems Inc.
Tapo C260 v1
TP-Link Systems Inc.
Tapo D235 v1
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability (CWE-284) affects TP-Link Tapo C260 v1 and D235 v1 devices, where a guest-level authenticated user can bypass intended access controls by exploiting a synchronization endpoint. The attacker can modify protected device settings despite limited privileges, leading to unauthorized device state manipulation. The vulnerability does not allow full code execution. The CVSS 4.0 score is 7.2, indicating high severity, with network attack vector, low attack complexity, no user interaction, and partial confidentiality and integrity impact but high availability and authorization impact.
Potential Impact
An attacker with guest-level authentication can change sensitive device configuration parameters without proper authorization. This unauthorized modification can affect device behavior and availability but does not allow execution of arbitrary code or full system compromise.
Mitigation Recommendations
No patch or official fix information is currently available. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is provided, restrict guest-level access and monitor device configurations for unauthorized changes.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- TPLink
- Date Reserved
- 2026-01-06T18:19:03.788Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 698b6f014b57a58fa11d374b
Added to database: 02/10/2026, 17:46:41 UTC
Last enriched: 08/05/2026, 13:34:24 UTC
Last updated: 09/10/2026, 22:11:50 UTC
Views: 306
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.