> IT-Sentinel.com

// Cybersecurity & IT News Aggregator - Real-time Threat Intelligence Feed

NEWS CVE
← messages.back_to_articles

> TVE-2026-04: TP-Link HTTP authentication bypass

[SOURCE] Taszk Labs [DATE: 28/04/2026 00:00] [LANGUAGE: EN]
An attacker sending a malformed HTTP POST request over LAN to a TP-Link Smart camera device can trigger the vulnerability described here. This report describes an authentication bypass vulnerability in the HTTP server implementation. The vulnerability we are disclosing in this advisory affected a wide range of TP-Link devices, including TAPO Smart Cameras. A TP-Link Security Advisory released was promised to be released in April 2026 after several delays, but this did not happen, without the vendor providing any explanation. Vulnerability Details The TAPO architecture can authenticate different account roles, one of them is the hub user. A whitelist introduced in recent builds (2025) limits this role to a few less sensitive actions.
[messages.read_original_source] →