TL;DR
Get tools and workshop supplies delivered free — and shop member deals
- Fast, free delivery on millions of items
- Access to Prime Big Deal Days deals on October 6–7
- Prime Video, Amazon Music and more included
TP-Link has released firmware updates for its Tapo C200 and C120 cameras after OPSWAT researchers reported flaws that could expose administrator access to someone on the same network. The C200 also had a separate flaw that could crash its HTTPS service or restart the device. Owners should install the latest firmware; the available report does not specify how many cameras were affected or whether either flaw was exploited.
TP-Link has released firmware updates for its Tapo C200 and C120 cameras after security researchers found a flaw that could give an attacker on the same network administrator access without a password. The company’s advisory lists the login-bypass vulnerability, CVE-2026-15315, as affecting the V1 hardware version of the C120 and the C200; a separate service-crash flaw affects the C200.
Security firm OPSWAT reported two vulnerabilities in the Tapo C200 series. Its researchers, Khoi Tran and Thai Do, found that the cameras’ HTTPS management interface had a second verification path that accepted a value provided by the camera during login as an authentication response. According to the report, a small number of requests could then create an administrator session without a password or an existing session.
The access could expose live video and stored recordings and allow changes to camera settings. The flaw, CVE-2026-15315, has a reported severity score of 8.7 and also affects the Tapo C120 in its V1 hardware version, according to TP-Link’s advisory as described by The Ambient. The separate issue, CVE-2026-15316, scores 7.1 and applies to the C200: oversized encrypted Wi-Fi credential data could crash the HTTPS service or cause the camera to restart.
Both attacks require an attacker to be on the same Wi-Fi network or already inside a trusted ecosystem, according to the report. TP-Link has issued firmware updates for the affected models. Owners need to install the latest version on each camera to address the login bypass and, on the C200, the service disruption flaw.
What Camera Owners Risk
The login bypass matters because administrator-level access could expose private footage and give an intruder control over camera settings. The risk is particularly personal for cameras used inside homes or as baby monitors. OPSWAT’s researchers said such access could include live video, night vision, crying detection and two-way audio.
The network requirement narrows the circumstances for an attack: the report does not describe remote access from anywhere on the internet through this flaw alone. But a person or device already connected to a household network could pose a different threat from an outside internet user. The separate C200 vulnerability has a different consequence, potentially interrupting camera service rather than granting the reported administrator access.
As an affiliate, we earn on qualifying purchases.
How the Tapo Flaws Differ
The reported vulnerabilities affect two camera models but do not have identical scope. CVE-2026-15315 is the authentication flaw affecting the C200 and the C120’s V1 hardware version. CVE-2026-15316 concerns oversized encrypted Wi-Fi credential data and is reported for the C200 alone.
The first issue involves the cameras’ HTTPS management interface and could produce an administrator session after a limited number of requests, according to OPSWAT’s findings. The second could make the C200’s HTTPS service unavailable or trigger a restart. The source report says TP-Link issued updates addressing both vulnerabilities, but does not provide firmware version numbers or release dates.
As an affiliate, we earn on qualifying purchases.
Exploit Reports and Patch Versions
The source material does not say whether attackers exploited either vulnerability, how many devices may be affected, or whether any users experienced unauthorized access or outages. It also does not identify the latest firmware version numbers, provide a complete model-by-model list of hardware revisions beyond the C120 V1 reference, or state when each update became available.
The reported same-network condition limits the described attack path, but the source does not explain what access an attacker would need to enter a trusted ecosystem or join a household network. The available information also does not establish whether the camera flaws were linked to any broader incident.
Wi-Fi security camera with night vision
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
Install Updates and Check Advisories
Tapo C200 and C120 owners should check the camera’s firmware settings or TP-Link support information and install the latest firmware available for their exact model and hardware version. C200 owners should update to address both reported flaws; C120 owners should verify that their hardware revision is covered by the advisory.
Further detail may come through TP-Link’s support notices or subsequent security reporting, including specific firmware versions and clarification of affected hardware revisions. Until then, the confirmed action is to apply the available update; the source material gives no separate timetable for additional disclosures.
As an affiliate, we earn on qualifying purchases.
Key Questions
Which TP-Link Tapo cameras are covered by the reported login flaw?
The login flaw, CVE-2026-15315, affects the Tapo C200 and the Tapo C120 V1, according to TP-Link’s advisory as described in the source report.
What could someone do through the login bypass?
OPSWAT researchers said an attacker on the same network could obtain an administrator session without a password or existing session. The reported access could include live video, stored recordings and camera configuration changes.
Does the C120 have the separate crash flaw?
The source report says CVE-2026-15316, which could crash the HTTPS service or restart a device, affects the C200 alone. It describes the C120 as affected by the login-bypass flaw in its V1 hardware version.
What should camera owners do?
Install the latest firmware available for the camera’s model and hardware version. The report says TP-Link issued updates addressing the login bypass on both models and the additional crash flaw on the C200.
Can the reported flaw be used by anyone on the internet?
The source says the attacks require the attacker to be on the same Wi-Fi network or within a trusted ecosystem. It does not describe the flaw as an attack available to any internet user without that access.
Source: rss
Fall Picks
fall essentials
As an affiliate, we earn on qualifying purchases.
