Executive brief
TP-Link Tapo security cameras (C260, D235, C211, C520WS) contain a path traversal flaw in their HTTP server that allows attackers to access files outside the intended directories. Authenticated attackers can extract sensitive system files and credentials, while unauthacated attackers can reach static assets. This puts customer data and camera configurations at risk of compromise.
Technical details
A path traversal vulnerability exists in the HTTP server's handling of GET requests across multiple Tapo camera models. The server performs path normalization before fully decoding URL-encoded input and falls back to the raw path when normalization fails, allowing attackers to bypass directory restrictions using crafted, URL-encoded traversal sequences. Authenticated users can disclose sensitive system files and credentials; unauthenticated attackers can access non-sensitive static assets. Network access to the camera's HTTP server is required; no user interaction is needed once the request is crafted. Patches are expected from TP-Link for the affected firmware versions.
Affected products
- TP-Link Tapo C260 v1
- TP-Link Tapo D235 v1
- TP-Link Tapo C211 v2
- TP-Link Tapo C520WS v2.6
Timeline
- 2026-02-10: disclosed