Logic Flaw in Tapo C520WS v2 API Authorization Mechanism
CVE-2026-34123

7HIGH

What is CVE-2026-34123?

A logic flaw in the API authorization mechanism of the Tapo C520WS v2 allows restricted accounts, such as hub users, to perform unauthorized operations. By exploiting this vulnerability, an attacker can craft requests that bypass the intended whitelist restrictions. This permits execution of sensitive operations, which could lead to device resets, configuration changes, and disruptions to normal functionality, consequently causing loss of availability and integrity.

Affected Version(s)

Tapo C520WS v2 0 < 1.2.6 Build 260528

References

CVSS V4

Score:
7
Severity:
HIGH
Confidentiality:
None
Integrity:
Low
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.