Disclosure summary
An attacker sending a malformed HTTP POST request over LAN to a TP-Link Smart camera device can trigger the vulnerability described here. This report describes an authentication by
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
Taszk Labs on taszk.io labs · RSS-1607e4940a26ed92bddbae2817056de542b
Open original source · Updated Apr 27, 2026
CVE-2026-34121: TP-Link HTTP authentication bypass
CVE mention in publisher metadata; check the original affected versions.
Original records & references
- NIST NVD record
- CVE Program record
- labs.taszk.io — Publisher advisory
PUBLISHED 2026-04-27T20:00:00-04:00
MODIFIED 2026-04-27T20:00:00-04:00
INGESTED 2026-10-08T12:20:17-04:00