TP-Link Tapo Camera Flaw Lets Attackers Gain Admin Access Without Password
Two flaws in TP-Link Tapo C200 cameras allow network-adjacent admin access without a password (CVE-2026-15315) or DoS (CVE-2026-15316); fixed in V5_1.4.6.
OPSWAT Unit 515 researchers discovered CVE-2026-15315, an authentication bypass in the Tapo C200's local HTTPS management interface on port 443, where an alternative verification path accepts a replayed device-generated value, letting unauthenticated network-adjacent attackers establish admin sessions. CVE-2026-15316 causes a denial-of-service crash in the camera's HTTPS service via oversized encrypted Wi-Fi credential data during onboarding. TP-Link confirmed both issues after the April 16, 2026 report and released firmware V5_1.4.6 on August 18, 2026. OPSWAT says additional potentially critical findings remain under coordinated disclosure.
- CVE-2026-15315: replayed challenge-response value grants admin session without knowing the password.
- Exploitation requires no user interaction, existing session, or physical access.
- CVE-2026-15316: oversized encrypted Wi-Fi credentials crash the camera's HTTPS service.
- Admins should update firmware and isolate cameras on restricted VLANs.
- OPSWAT reported more potentially critical Tapo flaws still under coordinated disclosure.
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-15315 | Authentication Bypass via Challenge Validation Flaw in TP-Link Tapo C120/C200 Cameras TP-Link Tapo C120 (v1) and Tapo C200 (v5) cameras contain an improper authentication vulnerability (CWE-287) in the login authentication verification module, rated high severity at CVSS 4.0 8.7. An attacker already present on the same local network as the camera (adjacent-network attack vector) can exploit weak validation of challenge parameters during the login handshake to bypass normal authentication and obtain administrative session tokens. With these tokens, the attacker can perform privileged management actions, gain unauthorized administrative access to the camera, and temporarily disrupt device services, causing a denial-of-service condition. All consumer and small-business deployments of these specific camera hardware/firmware versions are affected. A public proof-of-concept exists on GitHub, but EPSS is low (0.3% in 30 days) and the flaw is not in the CISA KEV catalog, so exploitation in the wild is not currently observed. Do: Check the hardware/firmware version of any Tapo C120 or C200 units in your environment (Tapo app > device settings > firmware) and apply the latest firmware TP-Link publishes for these models as soon as a fix is available, monitoring TP-Link's security advisory page. Because exploitation requires local network access, place cameras on a segregated IoT/guest VLAN that cannot reach trusted internal segments, and verify camera accounts, bindings, and recorded footage for signs of unauthorized administrative access. | 8.7 | <1% | PoC |
| massplausibly over 1 million deployed units across both models (order of magnitude, clearly an estimate) | |
| CVE-2026-15316 | Unauthenticated Input Validation DoS in TP-Link Tapo C200 v5 Configuration Service CVE-2026-15316 is an improper input validation flaw (CWE-20) in the configuration service of the TP-Link Tapo C200 camera (v5) that processes encrypted credential data. An attacker on an adjacent network can send oversized ciphertext values with no authentication required; insufficient validation causes exception-handling failures that crash or restart the device. The impact is a denial-of-service condition that temporarily disrupts HTTPS management and monitoring until the service recovers, with no confidentiality or integrity impact per the CVSS vector. Anyone running a Tapo C200 v5 camera is affected, though exploitation requires the attacker to reach the device's network (adjacent-network vector). No public proof-of-concept exists, the issue is not in CISA KEV, and EPSS estimates only a 0.2% chance of exploitation within 30 days. Do: Check your Tapo C200 firmware version in the Tapo app and apply TP-Link's firmware update for v5 when released. In the meantime, keep the camera's management interface off guest/WAN-exposed network segments and restrict it to trusted LANs, since the attack is unauthenticated and adjacent-network. Note that related reporting on TP-Link camera flaws (including eavesdropping issues) makes prompt patching of Tapo devices generally advisable. | 7.1 | <1% |
| masslikely millions of consumer installations (C200 is a top-selling budget Wi-Fi camera; only v5 units affected) |
Full article528 words · extracted from gbhackers.com · click to collapse
Security researchers have revealed two vulnerabilities in TP-Link’s Tapo C200 smart camera that could enable nearby network attackers to bypass administrator authentication or disrupt the device’s management service.
Khoi Tran and Thai Do from OPSWAT Unit 515 discovered these vulnerabilities, tracked as CVE-2026-15315 and CVE-2026-15316, during the company’s Critical Infrastructure Cybersecurity Graduate Fellowship Program. TP-Link addressed both issues in firmware version V5_1.4.6, which was released on August 18, 2026.
TP-Link Tapo Camera Flaw
The more critical vulnerability, CVE-2026-15315, is an authentication-bypass flaw in the camera’s local HTTPS management interface, which operates on port 443. The Tapo C200 uses a challenge-response process to verify a user’s knowledge of the administrator password before allowing an authenticated session.

However, researchers discovered an alternative verification method that incorrectly accepts a replayed value the camera originally returned during the authentication exchange.
As a result, an unauthenticated attacker with network access to the device can establish a valid administrative session without knowing, guessing, or recovering the camera’s password. Exploiting this vulnerability does not require user interaction, an existing authenticated session, or physical access to the camera.
Once an attacker establishes an administrative session, they can access privileged management functions and modify device settings. Depending on the available configuration options, this could jeopardize privacy-sensitive functions, including camera operation, live-stream access, and recorded footage.
This vulnerability highlights a recurring issue with embedded-device authentication: a challenge-response protocol is only secure if every possible verification path ensures proof of knowledge of the secret credential. Accepting a device-generated value as proof of authentication undermines this core requirement.

The second vulnerability, CVE-2026-15316, affects the camera’s Wi-Fi onboarding process. Researchers found that the affected firmware does not adequately validate the length of encrypted Wi-Fi credential data before it passes through cryptographic and configuration processing routines.
An attacker on the same network can submit an oversized encrypted credential value, triggering a crash in the camera’s HTTPS service. This denial-of-service condition could prevent legitimate administrators from accessing or managing the camera until the service recovers.
While this issue does not provide direct administrative access, it could affect the camera’s availability at critical moments, especially for cameras used in home monitoring, small-business surveillance, or other security operations.
TP-Link confirmed these vulnerabilities after OPSWAT reported them on April 16, 2026. CVE identifiers were assigned on August 13, followed by the vendor’s firmware release and advisory on August 18.
Users should promptly update their affected Tapo C200 devices to firmware version V5_1.4.6 or a later release. Administrators are also advised to avoid exposing camera management interfaces to untrusted networks, place IoT cameras on isolated VLANs where feasible, and restrict management access to authorized systems.
Additionally, OPSWAT stated that its researchers identified further issues during the assessment, including a potentially critical flaw related to camera compromise. The details of these findings remain under coordinated disclosure with TP-Link, and technical specifics have not yet been released.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.
Text extracted automatically; images, tables and formatting may be missing. Original: https://gbhackers.com/tp-link-tapo-camera-flaw/