> IT-Sentinel.com

// Cybersecurity & IT News Aggregator - Real-time Threat Intelligence Feed

NEWS CVE
← messages.back_to_articles

> CVE-2026-34121: TP-Link HTTP authentication bypass

[SOURCE] Taszk Labs [DATE: 28/04/2026 00:00] [LANGUAGE: EN]
An attacker sending a malformed HTTP POST request over LAN to a TP-Link Smart camera device can trigger the vulnerability described here. This report describes an authentication bypass vulnerability in the HTTP server implementation. The vulnerability we are disclosing in this advisory affected a wide range of TP-Link devices, including TAPO Smart Cameras. A TP-Link Security Advisory released in April 2026 contains this vulnerability as CVE-2026-34121. Vulnerability Details In the TAPO architecture, the DS module of the HTTP server running on the device is used for storing persistent configurations (]and other, dynamically generated content and also for performing actions on the device.
[messages.read_original_source] →