Impact
The vulnerability is a command injection flaw caused by insufficient sanitization of specific POST parameters used during configuration synchronization on the TP‑Link Tapo C260 v1. It allows an authenticated attacker to inject and execute arbitrary system commands, leading to full device compromise and impacting the confidentiality, integrity, and availability of the device and resources it connects to. Based on the description, it is inferred that malicious users could also use the flaw to perform reconnaissance, exfiltrate data, or pivot to other devices on the network.
Affected Systems
TP‑Link Systems Inc is the only vendor identified, with the affected product being the Tapo C260 v1. No other versions or products are mentioned in the CNA data. Thus only this model is known to be vulnerable.
Risk and Exploitability
The CVSS base score of 8.7 indicates high severity, and the EPSS score of 22% suggests a relatively high likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers must authenticate to the device; however, the description indicates that a guest or privileged user can send malicious POST requests during configuration synchronization. Therefore, remote attackers who can obtain credentials or use a compromised local account pose a significant risk, especially for devices exposed to the internet or unmanaged networks.
OpenCVE Enrichment