CVE-2026-34121 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

An authentication bypass vulnerability within the HTTP handling of the DS configuration service in TP-Link Tapo C520WS v2.6 was identified, due to inconsistent…
High CVSS: 8.7

CVE-2026-34121

An authentication bypass vulnerability within the HTTP handling of the DS configuration service in TP-Link Tapo C520WS v2.6 was identified, due to inconsistent parsing and authorization logic in JSON requests during authentication check. An unauthenticated attacker can append an authentication-exempt action to a request containing privileged DS do actions, bypassing authorization checks.

Successful exploitation allows unauthenticated execution of restricted configuration actions, which may result in unauthorized modification of device state.
Vendor
Tp-link
Product
Tapo C520ws Firmware
CWE
CWE-287
Yayın Tarihi
2026-04-02 18:16:28
Güncelleme
2026-04-06 20:24:48
Source Identifier
f23511db-6c3e-4e32-a477-6aa17d310630
KEV Date Added
-

Kategoriler

Referanslar