Popular TP-Link Tapo Cameras Patched To Prevent Unauthorised Local Access.
AIThis post was created with the assistance of artificial intelligence (AI).

TL;DR

Prime Big Deal Days · Oct 6–7Offer from Amazon

Get tools and workshop supplies delivered free — and shop member deals

  • Fast, free delivery on millions of items
  • Access to Prime Big Deal Days deals on October 6–7
  • Prime Video, Amazon Music and more included
Start your free Prime trial Free trial for eligible customers · Cancel anytime
As an affiliate, we earn on qualifying purchases.

TP-Link has released firmware updates for its Tapo C200 and C120 cameras after OPSWAT researchers reported flaws that could expose administrator access to someone on the same network. The C200 also had a separate flaw that could crash its HTTPS service or restart the device. Owners should install the latest firmware; the available report does not specify how many cameras were affected or whether either flaw was exploited.

TP-Link has released firmware updates for its Tapo C200 and C120 cameras after security researchers found a flaw that could give an attacker on the same network administrator access without a password. The company’s advisory lists the login-bypass vulnerability, CVE-2026-15315, as affecting the V1 hardware version of the C120 and the C200; a separate service-crash flaw affects the C200.

Security firm OPSWAT reported two vulnerabilities in the Tapo C200 series. Its researchers, Khoi Tran and Thai Do, found that the cameras’ HTTPS management interface had a second verification path that accepted a value provided by the camera during login as an authentication response. According to the report, a small number of requests could then create an administrator session without a password or an existing session.

The access could expose live video and stored recordings and allow changes to camera settings. The flaw, CVE-2026-15315, has a reported severity score of 8.7 and also affects the Tapo C120 in its V1 hardware version, according to TP-Link’s advisory as described by The Ambient. The separate issue, CVE-2026-15316, scores 7.1 and applies to the C200: oversized encrypted Wi-Fi credential data could crash the HTTPS service or cause the camera to restart.

Both attacks require an attacker to be on the same Wi-Fi network or already inside a trusted ecosystem, according to the report. TP-Link has issued firmware updates for the affected models. Owners need to install the latest version on each camera to address the login bypass and, on the C200, the service disruption flaw.

At a glance
updateWhen: Patches reported as issued; exact relea…
The developmentTP-Link issued firmware updates for Tapo C200 and C120 cameras to address a high-severity login bypass, plus a separate C200 flaw that could disrupt service.

What Camera Owners Risk

The login bypass matters because administrator-level access could expose private footage and give an intruder control over camera settings. The risk is particularly personal for cameras used inside homes or as baby monitors. OPSWAT’s researchers said such access could include live video, night vision, crying detection and two-way audio.

The network requirement narrows the circumstances for an attack: the report does not describe remote access from anywhere on the internet through this flaw alone. But a person or device already connected to a household network could pose a different threat from an outside internet user. The separate C200 vulnerability has a different consequence, potentially interrupting camera service rather than granting the reported administrator access.

Amazon

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

How the Tapo Flaws Differ

The reported vulnerabilities affect two camera models but do not have identical scope. CVE-2026-15315 is the authentication flaw affecting the C200 and the C120’s V1 hardware version. CVE-2026-15316 concerns oversized encrypted Wi-Fi credential data and is reported for the C200 alone.

The first issue involves the cameras’ HTTPS management interface and could produce an administrator session after a limited number of requests, according to OPSWAT’s findings. The second could make the C200’s HTTPS service unavailable or trigger a restart. The source report says TP-Link issued updates addressing both vulnerabilities, but does not provide firmware version numbers or release dates.

Amazon

Tapo C120 home security camera

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Exploit Reports and Patch Versions

The source material does not say whether attackers exploited either vulnerability, how many devices may be affected, or whether any users experienced unauthorized access or outages. It also does not identify the latest firmware version numbers, provide a complete model-by-model list of hardware revisions beyond the C120 V1 reference, or state when each update became available.

The reported same-network condition limits the described attack path, but the source does not explain what access an attacker would need to enter a trusted ecosystem or join a household network. The available information also does not establish whether the camera flaws were linked to any broader incident.

Amazon

Wi-Fi security camera with night vision

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Install Updates and Check Advisories

Tapo C200 and C120 owners should check the camera’s firmware settings or TP-Link support information and install the latest firmware available for their exact model and hardware version. C200 owners should update to address both reported flaws; C120 owners should verify that their hardware revision is covered by the advisory.

Further detail may come through TP-Link’s support notices or subsequent security reporting, including specific firmware versions and clarification of affected hardware revisions. Until then, the confirmed action is to apply the available update; the source material gives no separate timetable for additional disclosures.

Amazon

Indoor baby monitor camera

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Key Questions

The login flaw, CVE-2026-15315, affects the Tapo C200 and the Tapo C120 V1, according to TP-Link’s advisory as described in the source report.

What could someone do through the login bypass?

OPSWAT researchers said an attacker on the same network could obtain an administrator session without a password or existing session. The reported access could include live video, stored recordings and camera configuration changes.

Does the C120 have the separate crash flaw?

The source report says CVE-2026-15316, which could crash the HTTPS service or restart a device, affects the C200 alone. It describes the C120 as affected by the login-bypass flaw in its V1 hardware version.

What should camera owners do?

Install the latest firmware available for the camera’s model and hardware version. The report says TP-Link issued updates addressing the login bypass on both models and the additional crash flaw on the C200.

Can the reported flaw be used by anyone on the internet?

The source says the attacks require the attacker to be on the same Wi-Fi network or within a trusted ecosystem. It does not describe the flaw as an attack available to any internet user without that access.

Source: rss

FALL

Fall Picks

As an affiliate, we earn on qualifying purchases.

You May Also Like

Incident Reporting Procedures Every Foreman Should Follow

Step-by-step incident reporting procedures for foremen: scene control, OSHA deadlines, evidence, witness interviews, and corrective actions that stick.

Heat and Cold Stress Prevention Tips for Construction Sites

Practical jobsite guide to preventing heat and cold stress: hydration, acclimatization, PPE, symptom response, and a written plan foremen can use today.

Weekly Toolbox Talk Topics to Boost Safety Culture

Build stronger jobsite safety habits with practical weekly toolbox talk topics, crew questions, and follow-up steps that turn concerns into action.

OSHA Focus-Four Hazards: What Foremen Need to Know

Falls, struck-by, electrocution, caught-in: the four hazards responsible for most jobsite deaths — and exactly what foremen must check every shift.