TL;DR
Get home appliances delivered free — and shop member deals
- Fast, free delivery on millions of items
- Access to Prime Big Deal Days deals on October 6–7
- Prime Video, Amazon Music and more included
TP-Link has released firmware updates for its Tapo C200 and C120 cameras after researchers found a flaw that could let someone on the same network gain administrator access without a password. A separate vulnerability could crash or restart the C200. Camera owners should install the latest firmware; the reported attacks require access to the local network or a trusted ecosystem.
TP-Link has released firmware updates for its Tapo C200 and C120 cameras after security researchers found a login flaw that could give an attacker on the same network administrator access without a password. The update also addresses a separate bug that could disrupt the C200’s HTTPS service or restart the device.
Security firm OPSWAT reported two vulnerabilities in the Tapo C200 series. Its researchers, Khoi Tran and Thai Do, identified the more serious issue as CVE-2026-15315, which has a severity score of 8.7. TP-Link’s advisory also lists the Tapo C120 V1 hardware version as affected by that vulnerability.
The login bypass is in the cameras’ HTTPS management interface. According to OPSWAT’s technical account, a second verification path accepts a value supplied by the camera during login as an authentication response. With a small number of requests, an attacker can obtain an administrator session without a password or an existing session. That access could expose live video and stored recordings and allow changes to camera settings.
A second vulnerability, CVE-2026-15316, has a score of 7.1 and affects the C200 alone, according to the report. An oversized portion of encrypted Wi-Fi credential data can cause the camera’s HTTPS service to crash or make the device restart while it recovers. TP-Link has issued firmware updates addressing both flaws; the source report says owners need to install the latest version on each affected camera.
Local Network Access Could Expose Camera Feeds
The reported flaw matters because a camera’s administrator interface can control both what its owner sees and how the device is configured. If an attacker has the required network access, the bypass could expose private video and recordings, not merely information about the camera. The potential impact is especially sensitive when a camera is used to watch a child or another person at home.
OPSWAT said that a compromised camera used as a baby monitor could expose live video, night vision, crying detection and two-way audio. This is a description of what the researchers say the access could make available, not evidence in the source material that attackers have used the flaw against households.
The network condition also limits the reported exposure: an attacker must already be on the same Wi-Fi network or within a trusted ecosystem. That is a meaningful restriction, but it does not eliminate risk for households where an untrusted person or device has gained local access. Installing the firmware is the step TP-Link has provided to close the reported vulnerabilities.
As an affiliate, we earn on qualifying purchases.
Two Vulnerabilities, Different Effects
The two issues affect the camera line in different ways. CVE-2026-15315 is the authentication bypass and applies to the C200 series as well as the C120’s V1 hardware, according to the TP-Link advisory described in the report. Its consequence is potential access to administrator functions. CVE-2026-15316 is limited to the C200 and concerns service disruption from oversized encrypted Wi-Fi credential data.
Both reported attacks depend on an attacker first having access to the same Wi-Fi network or trusted ecosystem. The source does not describe a route for exploiting either issue remotely from an unrelated network. The distinction is relevant for owners evaluating the report: the login flaw may expose camera functions and content, while the second flaw may affect availability.
The report says TP-Link has published firmware updates for the affected models, but it does not provide firmware version numbers or release dates. Owners should check the update available for their particular camera and hardware version rather than assume that every Tapo model is affected. The supplied information identifies the C200 and C120 V1 for the login issue and the C200 for the service-disruption issue.
““live video, night vision, crying detection and two-way audio””
— OPSWAT researchers Khoi Tran and Thai Do, as quoted in the report
smart home security camera with night vision
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
Firmware Versions and Exploitation Reports
The supplied report does not specify the firmware version numbers, when each update was released, or whether updates install automatically. It also does not state how many devices may be affected or whether attackers have exploited either vulnerability in the wild. No evidence of real-world attacks is provided, so the possibility of access should not be presented as confirmation that cameras have been compromised.
The report says both flaws require an attacker to be on the same Wi-Fi network or within a trusted ecosystem, but does not give further detail about how that access might be obtained or what protections could limit it. It also mentions an unreported bug in its framing, but the supplied material does not provide details about that issue or say whether it is separate from the two listed vulnerabilities.
As an affiliate, we earn on qualifying purchases.
Owners Should Check Camera Firmware
Tapo C200 and C120 owners should check the firmware status of each camera and install the latest update available for their specific model and hardware version. The update is reported to fix the login bypass on affected C200 and C120 devices and, for the C200, the service-disruption flaw. Owners should confirm that the update has completed rather than assume a camera has been patched because an update is available.
Further detail may come from TP-Link or OPSWAT, particularly on affected firmware versions, update timing and the separately mentioned unreported bug. Until those points are clarified, the confirmed guidance in the source is to update affected cameras; the report does not describe a broader product recall or give evidence of exploitation.
As an affiliate, we earn on qualifying purchases.
Key Questions
Which TP-Link Tapo cameras are affected?
The login bypass, CVE-2026-15315, affects the Tapo C200 series and the Tapo C120 V1 hardware version, according to the report. The separate CVE-2026-15316 service-disruption flaw affects the C200 alone.
What could someone do with the login flaw?
OPSWAT researchers said an attacker on the same network could obtain an administrator session without a password or an existing session. The reported access could expose live video and stored recordings and permit changes to camera settings.
Does exploiting the flaw require access to my Wi-Fi?
According to the report, both attacks require an attacker to be on the same Wi-Fi network or within a trusted ecosystem. The supplied information does not describe exploitation from an unrelated external network.
What should camera owners do?
Check each affected camera for the latest available firmware and install it. The report does not give version numbers, so owners should check the update offered for their particular model and hardware version.
Have attackers used these flaws?
The source material does not report confirmed exploitation or camera compromises. It describes the vulnerabilities and their potential effects; whether attackers have used them is not established in the report.
Source: rss
NFL season / tailgating Picks
team gear
As an affiliate, we earn on qualifying purchases.
