ZeroHour
Story · 3 sources · 3 articlesfirst updated ()1

TP-Link Tapo C200 Zero-Days Allow Passwordless Admin Access and DoS; Third Critical Flaw Still Unpatched

What's new: New reporting added the TP-Link confirmation date of July 10, 2026, between the April 16, 2026 disclosure and the August 18, 2026 patch, and credited OPSWAT Unit 515 researchers Khoi Tran and Thai Do. All sources confirm both zero-days are fixed in firmware V5_1.4.6; the status of the third critical zero-day is unchanged — still unpatched, with details withheld pending a fix.
Merged summary · glm-5.3-flash · rewritten as coverage arrives

OPSWAT Unit 515 disclosed two zero-days in TP-Link Tapo C200 cameras: CVE-2026-15315, a replay-based authentication bypass granting admin access without the password, and CVE-2026-15316, an unauthenticated HTTPS denial-of-service. Both were fixed in firmware…

OPSWAT Unit 515 researchers Khoi Tran and Thai Do disclosed two zero-day vulnerabilities in the TP-Link Tapo C200 camera, widely used for baby/pet monitoring and SOHO security. CVE-2026-15315 is an authentication bypass in the camera's local HTTPS management interface on port 443, where an alternative verification path accepts a replayed device-generated challenge-response value, letting unauthenticated network-adjacent attackers establish administrative sessions without knowing the password, exposing live streams and stored recordings to surveillance. CVE-2026-15316 is an unauthenticated denial-of-service in which oversized encrypted Wi-Fi credential data sent during onboarding crashes the camera's HTTPS service. Exploitation of both requires network access to the camera but no user interaction, existing session, valid account, or physical access. OPSWAT reported the flaws to TP-Link on April 16, 2026; TP-Link confirmed them on July 10, 2026, and released firmware V5_1.4.6 on August 18, 2026, fixing both. OPSWAT says additional potentially critical Tapo findings remain under coordinated disclosure, including a third zero-day rated critical that could allow full camera compromise for use as a network foothold; details await an available fix. Recommended mitigations are updating to V5_1.4.6 and isolating cameras on restricted VLANs.

  • CVE-2026-15315: authentication bypass via replay in the Tapo C200's local HTTPS management interface on port 443; an alternative verification path accepts a replayed device-generated challenge-response value, granting admin sessions…
  • CVE-2026-15316: unauthenticated denial-of-service; oversized encrypted Wi-Fi credential data sent during onboarding crashes the camera's HTTPS service
  • Exploitation requires network-adjacent access to the camera but no user interaction, existing session, valid account, or physical access
  • Reported to TP-Link on April 16, 2026; TP-Link confirmed the flaws on July 10, 2026
  • Both flaws patched in firmware version V5_1.4.6, released August 18, 2026
  • A third zero-day rated critical, enabling full camera compromise for use as a network foothold, remains unpatched; details await an available fix, with additional potentially critical Tapo findings under coordinated disclosure
  • Discovered by OPSWAT Unit 515 researchers Khoi Tran and Thai Do
  • Recommended mitigations: update to firmware V5_1.4.6 and isolate cameras on restricted VLANs

Coverage timeline

  1. · 10h ago
    Infosecurity Magazine· 52
    Zero-Day Flaw in TP-Link Cameras Enables Eavesdropping

    OPSWAT disclosed two zero-days in TP-Link Tapo C200 cameras: CVE-2026-15315 authentication replay bypass enabling surveillance and CVE-2026-15316 denial-of-service, both patched in firmware.

  2. · 8h ago
    GBHackers· 48
    TP-Link Tapo Camera Flaw Lets Attackers Gain Admin Access Without Password

    Two flaws in TP-Link Tapo C200 cameras allow network-adjacent admin access without a password (CVE-2026-15315) or DoS (CVE-2026-15316); fixed in V5_1.4.6.

  3. · 7h ago
    Cyber Security News· 55
    TP-Link Cameras 0-Day Vulnerabilities Allow Attackers to Spy on Users

    Two zero-day flaws in TP-Link Tapo C200 cameras allowed authentication bypass and denial-of-service; fixed in firmware V5_1.4.6.

Vulnerabilities in this storyAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-15315
Authentication Bypass via Challenge Validation Flaw in TP-Link Tapo C120/C200 Cameras

TP-Link Tapo C120 (v1) and Tapo C200 (v5) cameras contain an improper authentication vulnerability (CWE-287) in the login authentication verification module, rated high severity at CVSS 4.0 8.7. An attacker already present on the same local network as the camera (adjacent-network attack vector) can exploit weak validation of challenge parameters during the login handshake to bypass normal authentication and obtain administrative session tokens. With these tokens, the attacker can perform privileged management actions, gain unauthorized administrative access to the camera, and temporarily disrupt device services, causing a denial-of-service condition. All consumer and small-business deployments of these specific camera hardware/firmware versions are affected. A public proof-of-concept exists on GitHub, but EPSS is low (0.3% in 30 days) and the flaw is not in the CISA KEV catalog, so exploitation in the wild is not currently observed.

Do: Check the hardware/firmware version of any Tapo C120 or C200 units in your environment (Tapo app > device settings > firmware) and apply the latest firmware TP-Link publishes for these models as soon as a fix is available, monitoring TP-Link's security advisory page. Because exploitation requires local network access, place cameras on a segregated IoT/guest VLAN that cannot reach trusted internal segments, and verify camera accounts, bindings, and recorded footage for signs of unauthorized administrative access.

8.7<1% PoC
  • tp-link tapo c120 firmware v1
  • tp-link tapo c200 firmware v5
massplausibly over 1 million deployed units across both models (order of magnitude, clearly an estimate)
CVE-2026-15316
Unauthenticated Input Validation DoS in TP-Link Tapo C200 v5 Configuration Service

CVE-2026-15316 is an improper input validation flaw (CWE-20) in the configuration service of the TP-Link Tapo C200 camera (v5) that processes encrypted credential data. An attacker on an adjacent network can send oversized ciphertext values with no authentication required; insufficient validation causes exception-handling failures that crash or restart the device. The impact is a denial-of-service condition that temporarily disrupts HTTPS management and monitoring until the service recovers, with no confidentiality or integrity impact per the CVSS vector. Anyone running a Tapo C200 v5 camera is affected, though exploitation requires the attacker to reach the device's network (adjacent-network vector). No public proof-of-concept exists, the issue is not in CISA KEV, and EPSS estimates only a 0.2% chance of exploitation within 30 days.

Do: Check your Tapo C200 firmware version in the Tapo app and apply TP-Link's firmware update for v5 when released. In the meantime, keep the camera's management interface off guest/WAN-exposed network segments and restrict it to trusted LANs, since the attack is unauthenticated and adjacent-network. Note that related reporting on TP-Link camera flaws (including eavesdropping issues) makes prompt patching of Tapo devices generally advisable.

7.1<1%
  • TP-Link Tapo C200 firmware v5
masslikely millions of consumer installations (C200 is a top-selling budget Wi-Fi camera; only v5 units affected)