logo

TP-Link Router Flaw Enables Authentication Bypass Through Password Recovery Mechanism 

ID: 91f41393-4108-5519-bde6-95293da6e05c

STIX ID: report--91f41393-4108-5519-bde6-95293da6e05c

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-01-20

Date Updated: 2026-04-22

Author: Divya

...
...

**TP-Link VIGI cameras (multiple series) are affected by a high-severity authentication bypass (CVE-2026-0629, CVSS 8.7) in the local web interface's password recovery flow that allows unauthenticated attackers on the same LAN to reset admin credentials via client-side state manipulation.** TP-Link released coordinated firmware patches across affected product lines (multiple builds and versions) beginning in late June 2025; organizations are advised to apply vendor firmware updates, verify deployments, enforce network segmentation for camera management networks, and restrict administrative interface access to trusted systems.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.