Security researcher Spaceraccoon disclosed an exploit chain affecting the TP-Link Tapo C260 camera that can be used to gain a shell on the device. The chain ties together CVE-2026-0651, CVE-2026-0652, and CVE-2026-0653, and public reporting describes the issues as enabling remote code execution against the webcam. A companion GitHub repository published by l0lsec provides a proof-of-concept implementation based on the research.
The public release of both the technical write-up and exploit code lowers the barrier for attackers targeting exposed or reachable Tapo C260 devices. For defenders, the disclosure means organizations and consumers using the camera should urgently identify affected deployments, restrict network exposure, monitor for signs of compromise, and apply any vendor fixes or mitigations as they become available.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
A GitHub repository named "tapo-c260-rce" was published with a proof-of-concept exploit chain for the TP-Link Tapo C260 camera, referencing the same three CVEs and the underlying research by Spaceraccoon.
A Spaceraccoon blog post disclosed an exploit chain affecting the TP-Link Tapo C260 camera, describing how shell access could be obtained via CVE-2026-0651, CVE-2026-0652, and CVE-2026-0653.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
spaceraccoon.dev
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.