CVE-2026-0651PoC(tp-link / tapo_c260)

LOWCVSS 7.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Prioritize remediation for tp-link tapo_c260 systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

A path traversal vulnerability was identified TP-Link Tapo C260 v1, D235 v1, C211 v2 and C520WS v2.6 within the HTTP server’s handling of GET requests. The server performs path normalization before fully decoding URL encoded input and falls back to using the raw path when normalization fails. An attacker can exploit this logic flaw by supplying crafted, URL encoded traversal sequences that bypass directory restrictions and allow access to files outside the intended web root. Successful exploitation may allow authenticated attackers to get disclosure of sensitive system files and credentials, while unauthenticated attackers may gain access to non-sensitive static assets.

3.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • tapo_c260
  • tapo_c260_firmware

Threat summary

  • Public PoC and exploit tooling are both present
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 4 signals
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • Peaked 3d ago at 1 mentions (2026-02-12); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Vendors
Products
tapo_c260tapo_c260_firmware

1 version affected across 2 products

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-02-12: 1Mentions · 2026-03-06: 1Mentions · 2026-03-10: 1Mentions · 2026-04-30: 1PoC Mentioned / Linked · 2026-02-12: 1PoC Mentioned / Linked · 2026-03-06: 1PoC Mentioned / Linked · 2026-03-10: 1PoC Mentioned / Linked · 2026-04-30: 1Exploit Tool / Code · 2026-03-10: 1Technical Details · 2026-02-12: 1Technical Details · 2026-03-10: 1Technical Details · 2026-04-30: 102-1203-0603-1004-30
Signal classification3 categories
PoC
250.0%
Disclosure
125.0%
Exploit
125.0%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-02-121
Disclosure1
2026-03-061
PoC1
2026-03-101
Exploit1
2026-04-301
PoC1
Full discourse4 posts
  • Nicolas Krassas@Dinosn
    PoC

    Getting a Shell on the Tapo C260 Webcam (CVE-2026-0651, CVE-2026-0652, CVE-2026-0653) https://spaceraccoon.dev/getting-shell-tapo-c260-webcam/

    Post summary

    The post refers to a proof‑of‑concept that demonstrates shell access on the Tapo C260 webcam via CVE‑2026‑0651, ‑0652, and ‑0653, but it does not include exploit code, patch information, or evidence of active exploitation.

    07034152.8K
    152.4K followersView on X
  • Mr. OS@ksg93rd
    Exploit

    #exploit #reversing 1⃣ Getting a Shell on the Tapo C260 Camera (CVE-2026-0651, CVE-2026-0652, CVE-2026-0653) https://spaceraccoon.dev/getting-shell-tapo-c260-webcam // Reverse-engineered Tapo C260 firmware reveals vulnerabilities enabling local file disclosure and full RCE through path traversal and configuration manipulation 2⃣ nginx UI Vulnerability https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-g9w5-qffc-6762 // CVE-2026-27944 (9.8/10) 3⃣ Patch diff to SYSTEM https://www.elastic.co/security-labs/patch-diff-to-system // Researchers utilized LLMs and patch diffing to develop a reliable privilege escalation exploit for Windows DWM via a UAF, demonstrating AI's growing role in vulnerability discovery and exploitation 4⃣ Reverse engineering Claude's CVE-2026-2796 exploit https://red.anthropic.com/2026/exploit ]-> Claude Code skill to support Android app's reverse engineering https://github.com/SimoneAvogadro/android-reverse-engineering-skill

    Post summary

    The post highlights the availability of actionable exploitation code for several CVEs, including PoC links and detailed attack methods, but does not report real‑world attacks or vendor patches.

    10024544
    3.2K followersView on X
  • Nicolas Krassas@Dinosn
    PoC

    CVE-2026-0651: TP-Link HTTP GET path traversal https://labs.taszk.io/blog/post/123_tp_path_traversal/

    Post summary

    The text announces CVE-2026-0651, a TP‑Link HTTP GET path traversal flaw, and provides a link that likely contains a PoC, with no evidence of active exploitation or patch information.

    00031980
    158.1K followersView on X
  • UNDERCODE TESTING@UndercodeUpdate
    Disclosure

    🚨 TP-Link Tapo #CVE-2026-0651 & #CVE-2026-0652: Unauthenticated RCE and File Disclosure in Millions of Smart Cameras — Full Technical Breakdown + Video https://undercodetesting.com/tp-link-tapo-cve-2026-0651-cve-2026-0652-unauthenticated-rce-and-file-disclosure-in-millions-of-smart-cameras-full-technical-breakdown-video/ Educational Purposes!

    Post summary

    The post announces TP‑Link Tapo CVE‑2026‑0651 and CVE‑2026‑0652, detailing unauthenticated remote code execution and file disclosure in millions of smart cameras, and provides a full technical breakdown and educational video.

    0000049
    392 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWtp-linktapo_c2601--
OStp-linktapo_c260_firmware---

Explore more