Junglewise Threat Intelligence

CVE-2026-34126: TP-Link Tapo cleartext Bluetooth communication during initialization

CVE-2026-34126 · Severity: info · CVSS 7.3 · Published 2026-05-28

Vendors: TP-Link.

Executive brief

A security vulnerability exists in several TP-Link Tapo smart home devices, including smart bulbs, power strips, and chimes, during their initial setup process. Because the Bluetooth communication used for setup is not encrypted, an attacker physically near the device could intercept or modify the setup data. This could allow an unauthorized person to gain control of the device before the owner finishes configuring it.

Technical details

A cleartext transmission vulnerability (CWE-319) exists in the Bluetooth initialization phase of TP-Link Tapo L535E (v1.0/v3.0), P300 (v1.0), and D100C (v1.0) devices. During the initial setup, sensitive configuration data is transmitted without encryption. An attacker within Bluetooth range can use sniffing or man-in-the-middle (MitM) techniques to eavesdrop on or manipulate the setup traffic. Successful exploitation could lead to unauthorized device control or the interception of setup credentials. TP-Link has released firmware updates (e.g., v1.4.1 for L535E and v1.4.2 for P300) to address these security concerns.

Affected products

  • TP-Link Tapo L535E v1.0, v3.0
  • TP-Link Tapo P300 v1.0
  • TP-Link Tapo D100C v1.0

Timeline

  • 2026-05-28: advisory: CVE-2026-34126 published by TP-Link
  • 2026-01-27: patched: Firmware 1.4.1 for Tapo L535E V3 released to enhance security
  • 2026-01-07: patched: Firmware 1.4.2 for Tapo P300 V1 released to enhance security

References