CVE-2026-0652General(tp-link / tapo_c260)

LOWCVSS 8.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Prioritize remediation for tp-link tapo_c260 systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

On TP-Link Tapo C260 v1, command injection vulnerability exists due to improper sanitization in certain POST parameters during configuration synchronization. An authenticated attacker can execute arbitrary system commands with high impact on confidentiality, integrity and availability. It may cause full device compromise.

3.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • tapo_c260
  • tapo_c260_firmware

Threat summary

  • Public PoC and exploit tooling are both present
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 2 signals
  • Technical details provided in 2 signals
  • General: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-02-12); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
tapo_c260tapo_c260_firmware

1 version affected across 2 products

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-02-12: 1Mentions · 2026-03-06: 1Mentions · 2026-03-10: 1PoC Mentioned / Linked · 2026-02-12: 1PoC Mentioned / Linked · 2026-03-10: 1Exploit Tool / Code · 2026-03-10: 1Technical Details · 2026-02-12: 1Technical Details · 2026-03-10: 102-1203-0603-10
Signal classification3 categories
General
133.3%
PoC
133.3%
Exploit
133.3%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-02-121
General1
2026-03-061
PoC1
2026-03-101
Exploit1
Full discourse3 posts
  • Nicolas Krassas@Dinosn
    PoC

    Getting a Shell on the Tapo C260 Webcam (CVE-2026-0651, CVE-2026-0652, CVE-2026-0653) https://spaceraccoon.dev/getting-shell-tapo-c260-webcam/

    Post summary

    The post announces a Proof of Concept that achieves shell access on the Tapo C260 webcam, referencing three CVEs but providing no concrete exploit details or patches within the text.

    07034152.8K
    152.4K followersView on X
  • Mr. OS@ksg93rd
    Exploit

    #exploit #reversing 1⃣ Getting a Shell on the Tapo C260 Camera (CVE-2026-0651, CVE-2026-0652, CVE-2026-0653) https://spaceraccoon.dev/getting-shell-tapo-c260-webcam // Reverse-engineered Tapo C260 firmware reveals vulnerabilities enabling local file disclosure and full RCE through path traversal and configuration manipulation 2⃣ nginx UI Vulnerability https://github.com/0xJacky/nginx-ui/security/advisories/GHSA-g9w5-qffc-6762 // CVE-2026-27944 (9.8/10) 3⃣ Patch diff to SYSTEM https://www.elastic.co/security-labs/patch-diff-to-system // Researchers utilized LLMs and patch diffing to develop a reliable privilege escalation exploit for Windows DWM via a UAF, demonstrating AI's growing role in vulnerability discovery and exploitation 4⃣ Reverse engineering Claude's CVE-2026-2796 exploit https://red.anthropic.com/2026/exploit ]-> Claude Code skill to support Android app's reverse engineering https://github.com/SimoneAvogadro/android-reverse-engineering-skill

    Post summary

    The post lists several new CVEs, shares PoC links and detailed exploit information, but lacks evidence of active exploitation or vendor patches.

    10024544
    3.2K followersView on X
  • UNDERCODE TESTING@UndercodeUpdate
    General

    🚨 TP-Link Tapo #CVE-2026-0651 & #CVE-2026-0652: Unauthenticated RCE and File Disclosure in Millions of Smart Cameras — Full Technical Breakdown + Video https://undercodetesting.com/tp-link-tapo-cve-2026-0651-cve-2026-0652-unauthenticated-rce-and-file-disclosure-in-millions-of-smart-cameras-full-technical-breakdown-video/ Educational Purposes!

    Post summary

    The tweet links to a technical breakdown and video on TP‑Link Tapo cameras’ CVE‑2026‑0651 and CVE‑2026‑0652, detailing unauthenticated RCE and file disclosure.

    0000049
    392 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWtp-linktapo_c2601--
OStp-linktapo_c260_firmware---

Explore more