Answer in brief
CVE-2026-0651 records a High severity (CVSS 7.8) vulnerability in Path Traversal on TP-Link Tapo D235, C211, C520WS and C260 via Local https. The current sources do not mark it as known exploited. The current feed maps TP Link Systems Inc./Tapo C211 v2 (generic), TP-Link Systems Inc./Tapo C260 v1 (generic), TP Link Systems Inc./Tapo C520WS v2.6 (generic), TP-Link Systems Inc./Tapo D235 v1 (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
Answer in brief
CVE-2026-0651 records a High severity (CVSS 7.8) vulnerability in Path Traversal on TP-Link Tapo D235, C211, C520WS and C260 via Local https. The current sources do not mark it as known exploited. The current feed maps TP Link Systems Inc./Tapo C211 v2 (generic), TP-Link Systems Inc./Tapo C260 v1 (generic), TP Link Systems Inc./Tapo C520WS v2.6 (generic), TP-Link Systems Inc./Tapo D235 v1 (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 7.8. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps TP Link Systems Inc./Tapo C211 v2 (generic), TP-Link Systems Inc./Tapo C260 v1 (generic), TP Link Systems Inc./Tapo C520WS v2.6 (generic), TP-Link Systems Inc./Tapo D235 v1 (generic). Check affected ranges and fixed versions before updating.
| Product | Affected versions | Fixed versions |
|---|---|---|
| cpe:2.3:h:tp-link:tapo_c260:1:*:*:*:*:*:*:* | Not reported | Not reported |
| cpe:2.3:o:tp-link:tapo_c260_firmware:*:*:*:*:*:*:*:* | Not reported | Not reported |
| Package | Affected range | Fixed version |
|---|---|---|
| TP Link Systems Inc./Tapo C211 v2generic | >=0 <1.5.4 Build 260702 Rel.7078n | 1.5.4 Build 260702 Rel.7078n |
| TP-Link Systems Inc./Tapo C260 v1generic | >=0 <1.1.9 Build 251226 Rel.55870n | 1.1.9 Build 251226 Rel.55870n |
| TP Link Systems Inc./Tapo C520WS v2.6generic | >=0 <1.2.4 Build 260326 Rel.24666n | 1.2.4 Build 260326 Rel.24666n |
| TP-Link Systems Inc./Tapo D235 v1generic | >=0 <1.2.2 Build 260210 Rel.27165n | 1.2.2 Build 260210 Rel.27165n |
Published upstream
Feb 10, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 4, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 4, 2026
A path traversal vulnerability was identified TP-Link Tapo C260 v1, D235 v1, C211 v2 and C520WS v2.6 within the HTTP server’s handling of GET requests. The server performs path normalization before fully decoding URL encoded input and falls back to using the raw path when normalization fails. An attacker can exploit this logic flaw by supplying crafted, URL encoded traversal sequences that bypass directory restrictions and allow access to files outside the intended web root. Successful exploitation may allow authenticated attackers to get disclosure of sensitive system files and credentials, while unauthenticated attackers may gain access to non-sensitive static assets.
Quoted source text, attributed separately from HOL analysis.
CVSS is 7.8. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps TP Link Systems Inc./Tapo C211 v2 (generic), TP-Link Systems Inc./Tapo C260 v1 (generic), TP Link Systems Inc./Tapo C520WS v2.6 (generic), TP-Link Systems Inc./Tapo D235 v1 (generic). Check affected ranges and fixed versions before updating.
| Product | Affected versions | Fixed versions |
|---|---|---|
| cpe:2.3:h:tp-link:tapo_c260:1:*:*:*:*:*:*:* | Not reported | Not reported |
| cpe:2.3:o:tp-link:tapo_c260_firmware:*:*:*:*:*:*:*:* | Not reported | Not reported |
| Package | Affected range | Fixed version |
|---|---|---|
| TP Link Systems Inc./Tapo C211 v2generic | >=0 <1.5.4 Build 260702 Rel.7078n | 1.5.4 Build 260702 Rel.7078n |
| TP-Link Systems Inc./Tapo C260 v1generic | >=0 <1.1.9 Build 251226 Rel.55870n | 1.1.9 Build 251226 Rel.55870n |
| TP Link Systems Inc./Tapo C520WS v2.6generic | >=0 <1.2.4 Build 260326 Rel.24666n | 1.2.4 Build 260326 Rel.24666n |
| TP-Link Systems Inc./Tapo D235 v1generic | >=0 <1.2.2 Build 260210 Rel.27165n | 1.2.2 Build 260210 Rel.27165n |
Published upstream
Feb 10, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 4, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 4, 2026
A path traversal vulnerability was identified TP-Link Tapo C260 v1, D235 v1, C211 v2 and C520WS v2.6 within the HTTP server’s handling of GET requests. The server performs path normalization before fully decoding URL encoded input and falls back to using the raw path when normalization fails. An attacker can exploit this logic flaw by supplying crafted, URL encoded traversal sequences that bypass directory restrictions and allow access to files outside the intended web root. Successful exploitation may allow authenticated attackers to get disclosure of sensitive system files and credentials, while unauthenticated attackers may gain access to non-sensitive static assets.
Quoted source text, attributed separately from HOL analysis.