www.infosecurity-magazine.com 16 Sept 2026, 10:00 UTC

TP-Link Tapo C200 Flaws Expose Camera Feeds to Network Attackers

TP-Link Tapo C200 Flaws Expose Camera Feeds to Network Attackers
CyberSIXT Evidence Panel
CISA KEV Not in KEV
Patch Patch Available

SECURITY researchers have disclosed two zero-day vulnerabilities in TP-Link’s Tapo C200 security camera, a model used for baby and pet monitoring, home security and small-office environments. OPSWAT said the flaws are CVE-2026-15315 and CVE-2026-15316, both rated high severity, and were fixed by TP-Link in firmware version V5_1.4.6, released on 18 August 2026.

CVE-2026-15315 is an authentication-bypass vulnerability involving replayed data. An attacker with network access to the camera could obtain a valid administrative session without knowing the owner’s password, then change settings and access privileged functions. OPSWAT said this could expose live video and stored recordings, enabling unauthorised surveillance.

CVE-2026-15316 is an unauthenticated denial-of-service flaw in the onboarding process: submitting an oversized encrypted credential value can crash the camera’s HTTPS service. Suzu Labs’ Dahvid Schloss said the authentication bypass is chiefly a concern for attackers already on the same network, although internet port-forwarding would increase the risk.

OPSWAT is also working with TP-Link on a separate zero-day vulnerability it rates critical, which it says could allow full camera compromise and provide a foothold inside the victim’s network. No technical details have been released for that issue, and OPSWAT said they will be shared after a fix becomes available. Users of the Tapo C200 should install firmware V5_1.4.6 where available and avoid exposing the camera directly to the internet.

View full article

Article by CyberSIXT