CVE-2026-34123

Severity CVSS v4.0:
HIGH
Type:
CWE-287 Authentication Issues
Publication date:
06/06/2026
Last modified:
06/06/2026

Description

On Tapo<br /> C520WS v2, restricted accounts (for example, hub users) are intended to execute<br /> only a limited set of low‑sensitivity operations. Due to a logic flaw in the<br /> device’s API authorization mechanism, an attacker can craft requests that<br /> leverage legitimate “method mapping” behavior to bypass whitelist restrictions,<br /> allowing restricted operations to be masked as permitted requests and executed.<br /> <br /> <br /> <br /> <br /> <br /> Successful<br /> exploitation may allow an attacker (with access to a restricted account) to<br /> execute unauthorized sensitive operations. <br /> Depending on the operation invoked, impact could include device<br /> resets, unintended configuration changes, or disruption of normal operation,<br /> leading to loss of availability and integrity of the device.