Popular TP-Link Tapo Cameras Patched To Prevent Unauthorised Local Access.
AIThis post was created with the assistance of artificial intelligence (AI).

TL;DR

Buying for a business?Offer from Amazon

Get business pricing on tools and workshop supplies

  • Business-only prices and quantity discounts
  • Tax-exempt purchasing
  • Multiple users, one account, clear invoices
As an affiliate, we earn on qualifying purchases.

TP-Link has released firmware updates for its Tapo C200 and C120 cameras after researchers found a login flaw that could give an attacker on the same network administrator access. A separate flaw can crash or restart the C200; owners need to install the latest firmware for their model.

TP-Link has patched a login flaw in its Tapo C200 and C120 cameras that could let someone already on the same network obtain administrator access without a password or an existing session. The update follows research by security firm OPSWAT; a separate vulnerability affecting the C200 could crash its HTTPS service or restart the device.

OPSWAT researchers Khoi Tran and Thai Do found that the cameras’ HTTPS management interface had a second verification path that accepted a value supplied by the camera during login as an authentication response. According to the researchers’ findings, a small number of requests could lead to an administrator session. That access could expose live video and stored recordings and permit configuration changes.

The login bypass is tracked as CVE-2026-15315 and has a reported severity score of 8.7. The source report says TP-Link lists the Tapo C120’s V1 hardware version as affected, alongside the C200. A separate issue, CVE-2026-15316, scores 7.1 and affects the C200 alone: an oversized amount of encrypted Wi-Fi credential data can crash its HTTPS service or cause the device to restart until it recovers.

TP-Link has issued firmware updates for both camera models to address the reported flaws. The source report advises owners to install the latest firmware on each camera. The bypass and crash attacks require an attacker to be on the same Wi-Fi network or within a trusted ecosystem, according to the report, which limits the described exposure to networks the attacker can already access.

At a glance
updateWhen: Firmware updates issued; the source rep…
The developmentTP-Link issued firmware updates for Tapo C200 and C120 cameras after OPSWAT researchers identified a same-network login bypass and a separate C200 service-crash flaw.

Camera Access at Home

The login bypass matters because cameras can carry sensitive footage and provide access to home monitoring functions. For households using a Tapo camera as a baby monitor, the researchers said an attacker could reach live video, night vision, crying detection and two-way audio. The report describes this as a potential consequence of administrator access, not as evidence that these functions were accessed in real incidents.

The same-network condition narrows the circumstances in which the described attack can occur, but it does not remove the need for a patch. Anyone who can access the affected network could potentially attempt the bypass, while the separate C200 flaw could disrupt the camera’s service or trigger a restart.

Two Flaws in Tapo Cameras

The findings concern two distinct vulnerabilities in TP-Link’s camera management software. CVE-2026-15315 is the authentication bypass reported for the C200 and the C120’s V1 hardware version. CVE-2026-15316 is a denial-of-service issue reported for the C200, linked to oversized encrypted Wi-Fi credential data.

Both reported attack paths require access to the same Wi-Fi network or a trusted ecosystem. The source material does not describe a remote internet-based route for either flaw. OPSWAT researchers disclosed the issues, and TP-Link has since issued firmware fixes for both models.

““live video, night vision, crying detection and two-way audio””

— OPSWAT researchers Khoi Tran and Thai Do

Scope and Exposure Details

The source report does not state how many cameras may be affected, how many users have installed the fixes, or whether either flaw has been exploited in the wild. It also does not provide the firmware version numbers or the date on which the updates were released. TP-Link’s advisory, as described in the report, specifically identifies the C120 V1 hardware version; the report does not provide equivalent hardware-version detail for the C200.

The described attacks require network access, but the source material does not say how often an attacker might already have that access or whether other Tapo models are affected. It reports no confirmed unauthorized access or outages tied to the vulnerabilities.

Install the Camera Firmware

Tapo C200 and C120 owners should check each camera for a firmware update and install the latest version available for that model. The source report says updates address both listed flaws, with the C200 update covering the login bypass and the crash issue. Owners should check TP-Link’s camera or support guidance for the applicable release and installation steps.

Further details that would clarify the scope include the affected firmware versions, the C200 hardware versions covered, and any later statement from TP-Link or OPSWAT about exploitation or patch adoption. The source material does not announce a further milestone or give a timetable for additional updates.

Key Questions

The login bypass, CVE-2026-15315, affects the Tapo C200 and the Tapo C120 V1 hardware version listed in TP-Link’s advisory, according to the report. The separate crash flaw, CVE-2026-15316, affects the C200.

What could an attacker do with the login bypass?

OPSWAT researchers said the flaw could provide administrator access, potentially exposing live video and stored recordings and allowing configuration changes. The described attack requires the person to be on the same network or within a trusted ecosystem.

Does the separate C200 flaw expose camera footage?

The report describes CVE-2026-15316 as a flaw that can crash the C200’s HTTPS service or restart the device after it receives oversized encrypted Wi-Fi credential data. It does not describe this issue as a way to view footage.

What should camera owners do?

Install the latest firmware available for each affected camera. The report says TP-Link issued updates for both models to address the reported vulnerabilities.

Source: rss

FALL

Fall Picks

As an affiliate, we earn on qualifying purchases.

You May Also Like

DIY Fabric Repairs: Essential Materials and Tools for Fixing Your Textiles

Learn the essential materials and tools for DIY fabric repairs to revive your textiles—discover what you need to get started today!

Essential Tools Every Crafter Needs: A Comprehensive Guide

Crafting enthusiasts will uncover crucial tools that elevate their projects, but what essentials truly make a difference in your creative journey?

How to Organize Your Crafting Supplies: Tools, Materials, and Fabric Care Essentials

Keep your crafting supplies in order with smart organization tips, but what essential fabric care techniques will transform your workspace? Discover more inside!