CVE-2026-0652

HIGH

TP-Link Tapo C260 Firmware < 1.1.9 - Authenticated OS Command Injection via Configuration Synchronization

Title source: llm
STIX 2.1

Description

On TP-Link Tapo C260 v1, command injection vulnerability exists due to improper sanitization in certain POST parameters during configuration synchronization. An authenticated attacker can execute arbitrary system commands with high impact on confidentiality, integrity and availability. It may cause full device compromise.

Scores

CVSS v3 8.8
EPSS 0.0018
EPSS Percentile 39.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-78
Status published
Products (1)
tp-link/tapo_c260_firmware < 1.1.9
Published Feb 10, 2026
Tracked Since Feb 18, 2026