<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Tapo — PoC Archive</title><link>https://poc.intelseclab.com/tags/tapo/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sun, 05 Jul 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/tapo/index.xml" rel="self" type="application/rss+xml"/><item><title>TP-Link Tapo C260 Unauthenticated-to-Root RCE Chain — CVE-2026-0651</title><link>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-0651-tapo-c260-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-0651-tapo-c260-rce/</guid><description>Critical severity — network · CVE-2026-0651 (chained with CVE-2026-0652, CVE-2026-0653). Status: Weaponized. Affects: TP-Link Tapo C260 IP camera (pre-patch firmware, shared /bin/main omnibus binary across models). Tags: iot, ip-camera, tp-link, tapo, path-traversal, command-injection, privilege-escalation, exploit-chain.</description><category>network</category><category>Critical</category><category>iot</category><category>ip-camera</category><category>tp-link</category><category>tapo</category><category>path-traversal</category><category>command-injection</category><category>privilege-escalation</category><category>exploit-chain</category></item></channel></rss>