CVE Explorer
CVE-2026-0653
On TP-Link Tapo C260 v1 and D235 v1, a guest‑level authenticated user can bypass intended access restrictions by sending crafted requests to a synchronization endpoint. This allows modification of protected device settings despite limited privileges. An attacker may change sensitive configuration parameters without authorization, resulting in unauthorized device state manipulation but not full code execution.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
affected · 2 assertions
{"defaultStatus":"unaffected","product":"Tapo D235 v1","vendor":"TP-Link Systems Inc.","versions":[{"lessThan":"1.2.2 Build 260210 Rel.27165n","status":"affected","version":"0","versionType":"custom"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:9481ce3492905ea5828612c0d8ee189c58cccb4b9f7dabcbf1a71f9a56b8b8e9 · sha256:513ac5a823970131… · /containers/cna/affected/1
{"defaultStatus":"unaffected","product":"Tapo C260 v1","vendor":"TP-Link Systems Inc.","versions":[{"lessThan":"1.1.9 Build 251226 Rel.55870n","status":"affected","version":"0","versionType":"custom"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:9481ce3492905ea5828612c0d8ee189c58cccb4b9f7dabcbf1a71f9a56b8b8e9 · sha256:513ac5a823970131… · /containers/cna/affected/0
Affected products and versions
2 source assertions{"defaultStatus":"unaffected","product":"Tapo D235 v1","vendor":"TP-Link Systems Inc.","versions":[{"lessThan":"1.2.2 Build 260210 Rel.27165n","status":"affected","version":"0","versionType":"custom"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:9481ce3492905ea5828612c0d8ee189c58cccb4b9f7dabcbf1a71f9a56b8b8e9 · sha256:513ac5a823970131… · /containers/cna/affected/1
{"defaultStatus":"unaffected","product":"Tapo C260 v1","vendor":"TP-Link Systems Inc.","versions":[{"lessThan":"1.1.9 Build 251226 Rel.55870n","status":"affected","version":"0","versionType":"custom"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:9481ce3492905ea5828612c0d8ee189c58cccb4b9f7dabcbf1a71f9a56b8b8e9 · sha256:513ac5a823970131… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":7.2,"baseSeverity":"HIGH","exploitMaturity":"NOT_DEFINED","privilegesRequired":"LOW","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpact":"L…
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:9481ce3492905ea5828612c0d8ee189c58cccb4b9f7dabcbf1a71f9a56b8b8e9 · sha256:513ac5a823970131… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-284","description":"CWE-284 Improper Access Control","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:9481ce3492905ea5828612c0d8ee189c58cccb4b9f7dabcbf1a71f9a56b8b8e9 · sha256:513ac5a823970131… · /containers/cna/problemTypes/0/descriptions/0
Source references
4 source assertions{"tags":["patch"],"url":"https://www.tp-link.com/en/support/download/tapo-c260/v1/"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:9481ce3492905ea5828612c0d8ee189c58cccb4b9f7dabcbf1a71f9a56b8b8e9 · sha256:513ac5a823970131… · /containers/cna/references/1
{"tags":["patch"],"url":"https://www.tp-link.com/en/support/download/tapo-d235/"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:9481ce3492905ea5828612c0d8ee189c58cccb4b9f7dabcbf1a71f9a56b8b8e9 · sha256:513ac5a823970131… · /containers/cna/references/3
{"tags":["patch"],"url":"https://www.tp-link.com/us/support/download/tapo-c260/v1/"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:9481ce3492905ea5828612c0d8ee189c58cccb4b9f7dabcbf1a71f9a56b8b8e9 · sha256:513ac5a823970131… · /containers/cna/references/0
{"tags":["vendor-advisory"],"url":"https://www.tp-link.com/us/support/faq/4960/"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:9481ce3492905ea5828612c0d8ee189c58cccb4b9f7dabcbf1a71f9a56b8b8e9 · sha256:513ac5a823970131… · /containers/cna/references/2
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.