Logic Flaw in Tapo C520WS v2 API Authorization Mechanism
CVE-2026-34123
7HIGH
What is CVE-2026-34123?
A logic flaw in the API authorization mechanism of the Tapo C520WS v2 allows restricted accounts, such as hub users, to perform unauthorized operations. By exploiting this vulnerability, an attacker can craft requests that bypass the intended whitelist restrictions. This permits execution of sensitive operations, which could lead to device resets, configuration changes, and disruptions to normal functionality, consequently causing loss of availability and integrity.
Affected Version(s)
Tapo C520WS v2 0 < 1.2.6 Build 260528
