TP-Link Cameras 0-Day Vulnerabilities Allow Attackers to Spy on Users
Two zero-day flaws in TP-Link Tapo C200 cameras allowed authentication bypass and denial-of-service; fixed in firmware V5_1.4.6.
OPSWAT researchers Khoi Tran and Thai Do found CVE-2026-15315, an authentication bypass in the Tapo C200's local HTTPS interface that lets network-adjacent attackers replay an authentication value to gain administrator access, and CVE-2026-15316, an unauthenticated denial-of-service in the Wi-Fi onboarding process that crashes the camera's HTTPS service. TP-Link was notified on April 16, 2026, confirmed the flaws on July 10, and released patches on August 18, 2026 in firmware V5_1.4.6. Exploitation requires local network access but no valid account, existing session, or user interaction, exposing live feeds and stored recordings to surveillance risk.
- CVE-2026-15315: authentication bypass via replay in local HTTPS challenge-response, granting admin access without the password
- CVE-2026-15316: oversized encrypted Wi-Fi credentials crash the HTTPS service, an unauthenticated denial-of-service
- Patched in firmware V5_1.4.6 released August 18, 2026; users should update immediately
- Admin access can expose live feeds and recordings, creating surveillance and privacy risk
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-15315 | Authentication Bypass via Challenge Validation Flaw in TP-Link Tapo C120/C200 Cameras TP-Link Tapo C120 (v1) and Tapo C200 (v5) cameras contain an improper authentication vulnerability (CWE-287) in the login authentication verification module, rated high severity at CVSS 4.0 8.7. An attacker already present on the same local network as the camera (adjacent-network attack vector) can exploit weak validation of challenge parameters during the login handshake to bypass normal authentication and obtain administrative session tokens. With these tokens, the attacker can perform privileged management actions, gain unauthorized administrative access to the camera, and temporarily disrupt device services, causing a denial-of-service condition. All consumer and small-business deployments of these specific camera hardware/firmware versions are affected. A public proof-of-concept exists on GitHub, but EPSS is low (0.3% in 30 days) and the flaw is not in the CISA KEV catalog, so exploitation in the wild is not currently observed. Do: Check the hardware/firmware version of any Tapo C120 or C200 units in your environment (Tapo app > device settings > firmware) and apply the latest firmware TP-Link publishes for these models as soon as a fix is available, monitoring TP-Link's security advisory page. Because exploitation requires local network access, place cameras on a segregated IoT/guest VLAN that cannot reach trusted internal segments, and verify camera accounts, bindings, and recorded footage for signs of unauthorized administrative access. | 8.7 | <1% | PoC |
| massplausibly over 1 million deployed units across both models (order of magnitude, clearly an estimate) | |
| CVE-2026-15316 | Unauthenticated Input Validation DoS in TP-Link Tapo C200 v5 Configuration Service CVE-2026-15316 is an improper input validation flaw (CWE-20) in the configuration service of the TP-Link Tapo C200 camera (v5) that processes encrypted credential data. An attacker on an adjacent network can send oversized ciphertext values with no authentication required; insufficient validation causes exception-handling failures that crash or restart the device. The impact is a denial-of-service condition that temporarily disrupts HTTPS management and monitoring until the service recovers, with no confidentiality or integrity impact per the CVSS vector. Anyone running a Tapo C200 v5 camera is affected, though exploitation requires the attacker to reach the device's network (adjacent-network vector). No public proof-of-concept exists, the issue is not in CISA KEV, and EPSS estimates only a 0.2% chance of exploitation within 30 days. Do: Check your Tapo C200 firmware version in the Tapo app and apply TP-Link's firmware update for v5 when released. In the meantime, keep the camera's management interface off guest/WAN-exposed network segments and restrict it to trusted LANs, since the attack is unauthenticated and adjacent-network. Note that related reporting on TP-Link camera flaws (including eavesdropping issues) makes prompt patching of Tapo devices generally advisable. | 7.1 | <1% |
| masslikely millions of consumer installations (C200 is a top-selling budget Wi-Fi camera; only v5 units affected) |
Full article579 words · extracted from cybersecuritynews.com · click to collapse
TP-Link Tapo C200 smart cameras were affected by two zero-day vulnerabilities that could allow attackers on the same network to bypass authentication or disrupt camera services.
The flaws, tracked as CVE-2026-15315 and CVE-2026-15316, were fixed in firmware version V5_1.4.6, released on August 18, 2026.
TP-Link Tapo cameras are widely deployed in homes and small businesses for remote video monitoring. The devices provide live video streaming, mobile-app integration, cloud-connected features, and local management services. However, their network connectivity can also create an entry point for attackers if security controls fail.
The vulnerabilities were discovered by OPSWAT researchers Khoi Tran and Thai Do as part of the company’s Critical Infrastructure Cybersecurity Graduate Fellowship Program. The researchers examined the Tapo C200 firmware and local communication functions in a controlled laboratory environment.
TP-Link Cameras 0-Day Vulnerabilities
CVE-2026-15315 is an authentication bypass vulnerability in the camera’s local HTTPS management interface. The Tapo C200 exposes its management service over HTTPS on port 443 and uses a challenge-response process to verify users before creating an authenticated session.
In a secure challenge-response system, the device sends a challenge to the user, and the client must return a correct response derived from the administrator’s password. OPSWAT found that the affected camera included an alternate verification path that did not properly enforce password-based validation.

Under certain conditions, an attacker could replay a value the camera generated during authentication. The device could then accept that value as valid and create an administrative session without requiring the attacker to know the camera password.
This means a threat actor with network access to a vulnerable Tapo C200 could potentially gain administrator-level access through only a small number of requests. No valid account, existing session, or user interaction is required.
Administrative access could allow an attacker to change device settings, alter network configuration, access privileged management functions, and potentially view privacy-sensitive camera features. This could expose live camera feeds or stored recordings, creating a serious surveillance and privacy risk for affected users.
The second flaw, CVE-2026-15316, is a denial-of-service vulnerability in the camera’s Wi-Fi onboarding process. During onboarding, the device processes encrypted Wi-Fi credential data.
OPSWAT found that the affected firmware did not properly validate the size of encrypted data before sending it to cryptographic and configuration-processing functions.

An unauthenticated attacker on the network could send an oversized encrypted credential value to the vulnerable service. The malformed input could crash the camera’s HTTPS service, preventing legitimate users from accessing or managing the device until the service recovers.
The issue does not require authentication or direct interaction with the victim. However, the attacker must have network access to the camera, such as a local Wi-Fi network, a compromised internal system, or an improperly exposed management interface.
OPSWAT reported the vulnerabilities to TP-Link on April 16, 2026. TP-Link confirmed the findings on July 10 and released patches on August 18. The company assigned CVE-2026-15315 and CVE-2026-15316 on August 13.
Users should update affected TP-Link Tapo C200 cameras to firmware version V5_1.4.6 or later immediately. Restrict camera management interfaces to trusted networks, and businesses should place IoT devices on separate network segments to reduce the impact of a compromise.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Abinayahttps://cybersecuritynews.com/
Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.
Text extracted automatically; images, tables and formatting may be missing. Original: https://cybersecuritynews.com/tp-link-cameras-0-day-vulnerabilities/