CVE-2026-34126 Details
Description
TP-Link has identified a vulnerability in Tapo L535E v1.0 and v3.0, Tapo P300 v1.0, and Tapo D100C v1.0, where Bluetooth communication during the initial setup phase is transmitted in cleartext without encryption. Bluetooth is only used during initialization. An attacker within the Bluetooth range could exploit this behavior using Bluetooth sniffing or man-in-the-middle techniques, which may allow eavesdropping on Bluetooth communication, manipulate transmitted setup data and potentially gain unauthorized control of the device during initialization. An attacker within the Bluetooth range could exploit this behavior using Bluetooth sniffing or man-in-the-middle techniques, which may allow eavesdropping on Bluetooth communication, manipulate transmitted setup data and potentially gain unauthorized control of the device during initialization. D100C is the chime delivered with your Tapo camera, and it is delivered with the following Tapo products: D130, D210, D235, D225, TD21, TDB21 and TD25
A vulnerability exists in TP-Link Tapo L535E (versions 1.0 and 3.0), Tapo P300 (version 1.0), and Tapo D100C (version 1.0). During the initial setup, Bluetooth communication is transmitted in cleartext without encryption. This vulnerability could be exploited by an attacker within Bluetooth range using sniffing or man-in-the-middle techniques, potentially allowing eavesdropping on the communication, manipulation of setup data, and unauthorized control of the device.
Users are advised to update their devices to the latest firmware version that addresses this vulnerability. For Tapo L535E, version 1.4.1 Build 251016 is available for download on the TP-Link website. Tapo P300 users can download version 1.4.2 Build 251219. For the Tapo D100C chime, firmware can be updated through the Tapo app.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 28, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.tp-link.com/en/support/download/tapo-l535e/v3/#Firmware-Release-Notes | TPLink | Release Notes |
| https://www.tp-link.com/en/support/download/tapo-p300/#Firmware-Release-Notes | TPLink | Release Notes |
| https://www.tp-link.com/jp/support/download/tapo-l535e/#Firmware-Release-Notes | TPLink | Release Notes |
| https://www.tp-link.com/jp/support/download/tapo-p300/#Firmware-Release-Notes | TPLink | Release Notes |
| https://www.tp-link.com/us/support/download/tapo-l535e/#Firmware-Release-Notes | TPLink | Release Notes |
| https://www.tp-link.com/us/support/faq/5106/ | TPLink | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-319 | Cleartext Transmission of Sensitive Information | TPLink |
Affected Products
| Product | Versions |
|---|---|
| tp-link tapo l535e firmware | 1.4.1 |
CPE
Remediation
| |
| tp-link tapo l535e | 1.0 3.0 |
CPE
Remediation
| |
| tp-link tapo p300 firmware | 1.4.0 1.4.2 |
CPE
Remediation
| |
| tp-link tapo p300 | 1.0 |
CPE
Remediation
| |
| tp-link tapo d100c firmware | 1.3.1 |
CPE
Remediation
| |
| tp-link tapo d100c | 1.0 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | TPLink |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 3, 2026 | Initial Analysis | [email protected] |
| May 28, 2026 | New CVE Received | TPLink |