Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-34123

Gravedad CVSS v4.0:
ALTA
Tipo:
CWE-287 Autenticación incorrecta
Fecha de publicación:
06/06/2026
Última modificación:
06/06/2026

Descripción

*** Pendiente de traducción *** On Tapo<br /> C520WS v2, restricted accounts (for example, hub users) are intended to execute<br /> only a limited set of low‑sensitivity operations. Due to a logic flaw in the<br /> device’s API authorization mechanism, an attacker can craft requests that<br /> leverage legitimate “method mapping” behavior to bypass whitelist restrictions,<br /> allowing restricted operations to be masked as permitted requests and executed.<br /> <br /> <br /> <br /> <br /> <br /> Successful<br /> exploitation may allow an attacker (with access to a restricted account) to<br /> execute unauthorized sensitive operations. <br /> Depending on the operation invoked, impact could include device<br /> resets, unintended configuration changes, or disruption of normal operation,<br /> leading to loss of availability and integrity of the device.