CVE Feed

    Dashboard / CVE / CVE-2026-34126

    CVE-2026-34126

    TP-Link has identified a vulnerability in Tapo L535E v1.0 and v3.0, Tapo P300 v1.0, and Tapo D100C v1.0, where Bluetooth communication during the initial setup phase is transmitted in cleartext without encryption. Bluetooth is only used during initialization. An attacker within the Bluetooth range could exploit this behavior using Bluetooth sniffing or man-in-the-middle techniques, which may allow eavesdropping on Bluetooth communication, manipulate transmitted setup data and potentially gain unauthorized control of the device during initialization.  An attacker within the Bluetooth range could exploit this behavior using Bluetooth sniffing or man-in-the-middle techniques, which may allow eavesdropping on Bluetooth communication, manipulate transmitted setup data and potentially gain unauthorized control of the device during initialization. D100C is the chime delivered with your Tapo camera, and it is delivered with the following Tapo products: D130, D210, D235, D225, TD21, TDB21 and TD25

    Published:May 28, 2026
    Last Modified:Jun 3, 2026
    EPS:May 28, 2026
    EPSS Score:0.00007
    CVSS Score:7.5

    Affected Products

    Vendor
    Tp-link
    Product
    Tapo D100c
    Vendor
    Tp-link
    Product
    Tapo D100c Firmware
    Vendor
    Tp-link
    Product
    Tapo L535e
    Vendor
    Tp-link
    Product
    Tapo L535e Firmware
    Vendor
    Tp-link
    Product
    Tapo P300
    Vendor
    Tp-link
    Product
    Tapo P300 Firmware
    Vendor
    Tp Link
    Product
    Tapo D100c

    Exploits

    No exploit reference

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High