Junglewise Threat Intelligence

CVE-2026-34121: TP-Link Tapo C520WS authentication bypass in DS configuration service

CVE-2026-34121 · Severity: high · CVSS 8.8 · Published 2026-04-02

Technologies: TP-Link Tapo C520WS, TP-Link Tapo C520ws Firmware. Vendors: TP-Link.

Executive brief

A security vulnerability has been identified in the TP-Link Tapo C520WS outdoor security camera. This flaw allows an unauthorized person on the same network to bypass security checks and change the camera's settings. This could lead to unauthorized access to the device, modification of its configuration, or a loss of control over the security camera's operations.

Technical details

An authentication bypass vulnerability exists in the DS configuration service of TP-Link Tapo C520WS v2.6. The flaw is caused by inconsistent parsing and authorization logic when handling JSON requests during authentication checks. Specifically, an unauthenticated attacker can craft a request that appends an authentication-exempt action alongside privileged 'DS do' actions. This allows the attacker to bypass authorization checks and execute restricted configuration commands. The vulnerability is reachable via the local network (adjacent) and requires no user interaction. TP-Link has released firmware version 1.2.4 Build 260326 Rel.24666n to address this issue.

Affected products

  • TP-Link Tapo C520WS v2.6 before 1.2.4 Build 260326 Rel.24666n

Timeline

  • 2026-04-02: disclosed
  • 2026-04-02: advisory

References

Related threats