VYPR

D235

by TP-Link

CVEs (1)

  • CVE-2026-0653MedFeb 10, 2026
    risk 0.42cvss 6.5epss 0.00

    On TP-Link Tapo C260 v1 and D235 v1, a guest‑level authenticated user can bypass intended access restrictions by sending crafted requests to a synchronization endpoint. This allows modification of protected device settings despite limited privileges. An attacker may change…