Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-34121

Gravedad CVSS v4.0:
ALTA
Tipo:
CWE-287 Autenticación incorrecta
Fecha de publicación:
02/04/2026
Última modificación:
06/04/2026

Descripción

*** Pendiente de traducción *** An authentication bypass vulnerability within the HTTP handling of the DS configuration service in TP-Link Tapo C520WS v2.6 was identified, due to inconsistent parsing and authorization logic in JSON requests during authentication check. An unauthenticated attacker can append an authentication-exempt action to a request containing privileged DS do actions, bypassing authorization checks.<br /> <br /> Successful exploitation allows unauthenticated execution of restricted configuration actions, which may result in unauthorized modification of device state.

Productos y versiones vulnerables

CPE Desde Hasta
cpe:2.3:o:tp-link:tapo_c520ws_firmware:*:*:*:*:*:*:*:* 1.2.4 (excluyendo)
cpe:2.3:h:tp-link:tapo_c520ws:2.6:*:*:*:*:*:*:*