CVE-2026-0651 Details
Description
A path traversal vulnerability was identified TP-Link Tapo C260 v1, D235 v1, C211 v2 and C520WS v2.6 within the HTTP server’s handling of GET requests. The server performs path normalization before fully decoding URL encoded input and falls back to using the raw path when normalization fails. An attacker can exploit this logic flaw by supplying crafted, URL encoded traversal sequences that bypass directory restrictions and allow access to files outside the intended web root. Successful exploitation may allow authenticated attackers to get disclosure of sensitive system files and credentials, while unauthenticated attackers may gain access to non-sensitive static assets.
A path traversal vulnerability has been identified in the TP-Link Tapo C260 v1 camera. This issue arises from improper handling of specific GET request paths over HTTPS, allowing local unauthenticated users to probe the filesystem and determine the existence of certain files on the device. However, this vulnerability does not permit reading, writing, or executing code.
Users are advised to update to the latest firmware version. Instructions for downloading the update are available on the TP-Link Tapo C260 v1 support page.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 11, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | TPLink |
Affected Products
| Product | Versions |
|---|---|
| tp-link tapo c260 firmware | < 1.1.9 |
CPE
Remediation
| |
| tp-link tapo c260 | 1 |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 4, 2026 | CVE Modified | TPLink |
| Jun 17, 2026 | CVE Modified | TPLink |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 2, 2026 | CVE Modified | TPLink |
| Mar 13, 2026 | CVE Modified | TPLink |
| Feb 13, 2026 | Initial Analysis | [email protected] |
| Feb 10, 2026 | New CVE Received | TPLink |