TP-Link Router Flaw Enables Authentication Bypass Through Password Recovery Mechanism
ID: 91f41393-4108-5519-bde6-95293da6e05c
STIX ID: report--91f41393-4108-5519-bde6-95293da6e05c
Feed Name: GBHackers
**TP-Link VIGI cameras (multiple series) are affected by a high-severity authentication bypass (CVE-2026-0629, CVSS 8.7) in the local web interface's password recovery flow that allows unauthenticated attackers on the same LAN to reset admin credentials via client-side state manipulation.** TP-Link released coordinated firmware patches across affected product lines (multiple builds and versions) beginning in late June 2025; organizations are advised to apply vendor firmware updates, verify deployments, enforce network segmentation for camera management networks, and restrict administrative interface access to trusted systems.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
