Impact
A path traversal flaw exists in TP‑Link Tapo devices’ HTTP server, where the server first normalizes the requested URL before fully decoding it. When the normalization fails, the server falls back to using the raw, encoded path. An attacker can submit crafted URL‑encoded traversal sequences in a GET request that bypass the directory restrictions, enabling access to files outside the expected web root. Successful exploitation can expose sensitive system files and credentials to an authenticated attacker, while unauthenticated users may retrieve non‑sensitive static assets.
Affected Systems
Vendors and product models affected are TP‑Link Systems Inc., specifically the Tapo C260 v1, D235 v1, C211 v2, and C520WS v2.6. No other firmware versions are listed as vulnerable, and the issue appears limited to the current official releases referenced in the vendor’s support links.
Risk and Exploitability
With a CVSS score of 6.9 the vulnerability is considered moderate. The EPSS score is below 1 %, indicating a very low current exploitation probability, and the issue is not listed in CISA’s KEV catalog. Based on the description, it is inferred that the likely attack scenario involves an attacker with local network access who can reach the device’s HTTPS interface; the attacker could supply crafted URL‑encoded traversal sequences that bypass directory restrictions and read files outside the web root. If the device is authenticated, the attacker can obtain sensitive files, but even unauthenticated users may read publicly served assets. Because the flaw is purely logical and does not require exploitation of a separate service, its impact is confined to the device and the local network, making it a localized but potentially damaging threat.
OpenCVE Enrichment