> CVE-2026-0651: TP-Link HTTP GET path traversal
[DATE: 28/04/2026 00:00]
[LANGUAGE: EN]
An attacker sending a malformed HTTP POST request over LAN to a TP-Link Smart camera device can trigger the vulnerability described here.
This report describes a path traversal which can lead to leaking secrets.
The vulnerability we are disclosing in this advisory affected a wide range of TP-Link devices, including TAPO Smart Cameras. A TP-Link Security Advisory released in January 2026 and updated in April 2026 contains this vulnerability as CVE-2026-0651.
Vulnerability Details We identified a path traversal vulnerability in the way te HTTP server of TAPO devices handles GET requests. The parser only gives access to specific directories without authentication.