TL;DR
Get business pricing on your home office setup
- Business-only prices and quantity discounts
- Tax-exempt purchasing
- Multiple users, one account, clear invoices
TP-Link has released firmware updates for its Tapo C200 and C120 cameras after OPSWAT researchers identified a flaw that could give an attacker on the same network administrator access. A separate service-crash vulnerability affects the C200. Owners should install the latest firmware; the reported attacks require prior access to the local network.
TP-Link has released firmware updates for its Tapo C200 and C120 cameras after security researchers found a flaw that could let someone on the same network gain administrator access without a password. The more serious vulnerability, tracked as CVE-2026-15315, could expose camera video, recordings and settings; a second flaw affects the C200 and can disrupt its service or restart the device.
Security firm OPSWAT identified two vulnerabilities in the cameras’ management interfaces. Its researchers, Khoi Tran and Thai Do, reported that CVE-2026-15315 affects the Tapo C200 series and also the Tapo C120 in its V1 hardware version, according to TP-Link’s advisory. The vulnerability has a reported severity score of 8.7.
The authentication issue involves a second verification path in the cameras’ HTTPS management interface. The researchers said it accepts a value supplied by the camera during login as an authentication response. After a small number of requests, an attacker could obtain an administrator session without a password or an existing session, potentially reaching live video, stored recordings and configuration controls.
A separate vulnerability, CVE-2026-15316, has a reported score of 7.1 and affects the C200 alone. OPSWAT said an oversized portion of encrypted Wi-Fi credential data can cause the HTTPS service to crash or the camera to restart until it recovers. TP-Link has issued updates for both models that address the reported flaws. Owners need to install the latest firmware on each affected camera.
Local Network Access Raises Privacy Risks
The authentication flaw matters because a camera can reveal private activity inside a home, and administrator access could provide more than a view of a live feed. Depending on how a camera is used, access to recordings and settings could expose household routines or allow an intruder to change device configuration. The risk is especially sensitive when a camera also serves as a baby monitor.
OPSWAT’s researchers said that, in that use case, exposure could include live video, night vision, crying detection and two-way audio. That is a description of potential access if an attacker exploits the flaw, not evidence that any particular camera was accessed or that recordings have been taken.
The network requirement narrows the reported attack conditions: an attacker would first need to be on the same Wi-Fi network or inside a trusted ecosystem. It does not make the flaw harmless. A person who already has access to a household network could potentially use the camera vulnerability to reach sensitive functions without knowing the camera password.
Two Flaws, Different Camera Effects
The reported issues affect overlapping but distinct models and functions. CVE-2026-15315 is the login bypass, reported for the C200 series and the C120 V1 hardware version. CVE-2026-15316 is the service-disruption flaw and, according to the source report, applies only to the C200.
Both vulnerabilities require an attacker to have access to the local network or a trusted ecosystem before attempting the described attack. The source material does not say that the flaws can be exploited remotely over the internet by someone with no network access. It also does not report confirmed exploitation in the wild. The practical response identified by TP-Link is to update the firmware for each affected camera.
“The researchers said the authentication flaw could expose “live video, night vision, crying detection and two-way audio” when a camera is used as a baby monitor.”
— OPSWAT researchers Khoi Tran and Thai Do, as described in The Ambient report
Exploitation and Update Details Unreported
The supplied report does not state whether anyone has exploited either vulnerability, whether attackers have accessed camera footage, or how many devices may be affected. It also does not provide the firmware version numbers, release dates, or a full model-by-model update schedule. C120 owners should pay particular attention to the V1 hardware-version qualification given in the advisory.
The report describes both attacks as requiring a position on the same Wi-Fi network or within a trusted ecosystem. It does not establish whether other attack routes exist, or whether additional Tapo models are affected. No conclusion about those questions can be drawn from the information provided.
Owners Should Check Camera Firmware
Owners of a Tapo C200 or C120 should check the camera’s firmware and install the latest available update, following TP-Link’s instructions. C200 owners should update to address both the login bypass and the service-disruption flaw; C120 owners should check whether their device is the V1 hardware version covered by the advisory and apply its available update.
Further useful information would include the affected and fixed firmware version numbers, the dates updates became available, and any later reports of exploitation or additional affected models. The source material does not specify when TP-Link will publish further details, so owners should consult the company’s current product support and security information.
Key Questions
Which Tapo cameras are reported as affected?
The login bypass, CVE-2026-15315, affects the Tapo C200 series and the Tapo C120 V1 hardware version, according to the report. The separate service-crash flaw, CVE-2026-15316, affects the C200 alone.
What could an attacker do with the login bypass?
OPSWAT researchers said an attacker on the same network could obtain administrator access without a password or existing session. That could expose live video, stored recordings and camera settings.
Can the reported flaws be exploited by anyone on the internet?
The report says an attacker must first be on the same Wi-Fi network or within a trusted ecosystem. It does not describe exploitation by someone with no local-network access.
How can owners address the vulnerabilities?
TP-Link has issued firmware updates for the affected models. Owners should check each camera and install its latest available firmware, paying attention to the C120 V1 hardware-version detail.
Has there been confirmed exploitation?
The supplied report does not say whether either vulnerability has been exploited or whether any camera footage has been accessed. Those points remain unconfirmed in the available information.
Source: rss
Fall Picks
fall essentials
As an affiliate, we earn on qualifying purchases.
