Junglewise Threat Intelligence

CVE-2026-34123: TP-Link Tapo C520WS auth bypass in API authorization mechanism

CVE-2026-34123 · Severity: info · CVSS 7 · Published 2026-06-06

Technologies: TP-Link Tapo C520WS. Vendors: TP-Link.

Executive brief

TP-Link Tapo C520WS security cameras contain a flaw that allows users with restricted access to bypass security controls. By sending specially crafted requests, an attacker with a low-privilege account can perform sensitive actions they should not be allowed to do. This could result in the device being reset, settings being changed, or the camera becoming unavailable for monitoring.

Technical details

A logic flaw exists in the API authorization mechanism of the TP-Link Tapo C520WS v2. The vulnerability stems from how the device handles 'method mapping' during API requests, which can be leveraged to bypass whitelist restrictions. An authenticated attacker with a restricted account (such as a hub user) can craft requests that mask unauthorized sensitive operations as legitimate, permitted ones. Successful exploitation allows for unauthorized configuration changes, device resets, or denial-of-service conditions. The vendor has released firmware updates to address this and other vulnerabilities on the product support page.

Affected products

  • TP-Link Tapo C520WS v2

Timeline

  • 2026-06-05: disclosed
  • 2026-06-06: advisory

References

Related threats