Getting a Shell on the Tapo C260 Webcam (CVE-2026-0651, CVE-2026-0652, CVE-2026-0653)
As shared in my previous blogpost, I reverse-engineered the TP-Link Tapo C260 webcam for the SPIRITCYBER IoT hardware hacking contest. Despite being one of the latest Tapo webcams, I was able to discover some pretty interesting vulnerabilities – local file disclosure (CVE-2026-0651), guest-privilege Remote Code Execution (CVE-2026-0652), and privilege escalation […]
