Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Microsoft 365 Suffers Widespread Outage with 502 and 503 Errors
September 16, 2026
VectraRAT Malware for Rent, Threatens Windows PCs
September 16, 2026
GhostCode Phishing Kit Bypasses Microsoft 365 MFA to Hijack Accounts
September 16, 2026
Home/CyberSecurity News/Critical TP-Link Tapo Camera Vulnerabilities Let Attackers Spy on Users
CyberSecurity News

Critical TP-Link Tapo Camera Vulnerabilities Let Attackers Spy on Users

Key Takeaways Two critical zero-day vulnerabilities (CVE-2026-15315 and CVE-2026-15316) were discovered in TP-Link Tapo C200 smart cameras. These flaws could enable an attacker on the same network to...

David kimber
David kimber
September 16, 2026 3 Min Read
4 0

Key Takeaways

  • Two critical zero-day vulnerabilities (CVE-2026-15315 and CVE-2026-15316) were discovered in TP-Link Tapo C200 smart cameras.
  • These flaws could enable an attacker on the same network to bypass authentication for administrative access or trigger a denial-of-service condition.
  • The vulnerabilities primarily affect the Tapo C200 model and were patched in firmware version V5_1.4.6, released on August 18, 2026.
  • The issues were identified by OPSWAT researchers Khoi Tran and Thai Do.

Critical Flaws Expose TP-Link Tapo Cameras to Spying and Disruption

TP-Link Tapo C200 smart cameras, popular for their use in home and small business surveillance, were recently found to harbor two significant zero-day vulnerabilities. These security defects could allow threat actors operating on the same network to circumvent authentication mechanisms or incapacitate camera services, creating substantial privacy and operational risks for users.

Table Of Content

  • Key Takeaways
  • Critical Flaws Expose TP-Link Tapo Cameras to Spying and Disruption
  • Authentication Bypass: CVE-2026-15315
  • Denial-of-Service Vulnerability: CVE-2026-15316
  • What You Should Do

The identified flaws, officially cataloged as CVE-2026-15315 and CVE-2026-15316, have since been addressed by TP-Link. A crucial firmware update, version V5_1.4.6, rolled out on August 18, 2026, contains the necessary fixes. The widespread deployment of TP-Link Tapo cameras, which offer live video streaming, mobile app integration, and cloud functionalities, underscores the importance of these patches. While these network-connected features provide convenience, they also present potential entry points for adversaries if not properly secured.

The discovery of these vulnerabilities emerged from the diligent work of OPSWAT researchers Khoi Tran and Thai Do. Their findings were part of OPSWAT’s Critical Infrastructure Cybersecurity Graduate Fellowship Program. The research team meticulously analyzed the Tapo C200 firmware and its local communication protocols within a controlled lab environment to uncover these weaknesses.

Authentication Bypass: CVE-2026-15315

CVE-2026-15315 points to a severe authentication bypass vulnerability affecting the camera’s local HTTPS management interface. The Tapo C200 exposes its management service via HTTPS on port 443, employing a challenge-response mechanism to authenticate users before establishing a secure session. This system typically requires the device to issue a challenge, to which the client must respond with a value derived from the administrator’s password, confirming user legitimacy.

However, OPSWAT’s investigation revealed an alternative verification pathway within the affected camera that failed to adequately enforce password-based validation. This lapse meant that under specific circumstances, an attacker could reuse a value previously generated by the camera during an authentication attempt. The device would then erroneously accept this replayed value as valid, granting an administrative session without the attacker ever needing to know the actual camera password.

This vulnerability is particularly concerning because it enables a threat actor with network access to a vulnerable Tapo C200 to achieve administrator-level access with minimal effort. Critically, no valid account, pre-existing session, or user interaction is required for exploitation. Gaining administrative control could allow an attacker to modify device settings, reconfigure network parameters, access privileged management functions, and potentially view sensitive camera feeds or stored recordings. This capability poses a significant risk to privacy and could facilitate unauthorized surveillance.

Denial-of-Service Vulnerability: CVE-2026-15316

The second identified flaw, CVE-2026-15316, is a denial-of-service (DoS) vulnerability located within the camera’s Wi-Fi onboarding process. During this process, the device handles encrypted Wi-Fi credential data. OPSWAT discovered that the vulnerable firmware did not properly validate the size of this encrypted data before forwarding it to cryptographic and configuration-processing functions.

An unauthenticated attacker on the same network could exploit this by sending an excessively large encrypted credential value to the vulnerable service. This malformed input would cause the camera’s HTTPS service to crash, rendering the device inaccessible and unmanageable for legitimate users until the service eventually recovers. While authentication is not required, the attacker must possess network access to the camera, which could be via a local Wi-Fi network, a compromised internal system, or an improperly exposed management interface.

OPSWAT reported the vulnerabilities to TP-Link on April 16, 2026. TP-Link acknowledged the findings on July 10, assigned CVE-2026-15315 and CVE-2026-15316 on August 13, and subsequently released the necessary patches on August 18.

What You Should Do

  • Immediately update all affected TP-Link Tapo C200 cameras to firmware version V5_1.4.6 or a later version.
  • Restrict access to camera management interfaces to trusted internal networks only. Avoid exposing them directly to the internet.
  • For businesses, segment IoT devices like smart cameras onto separate network segments or VLANs. This practice limits the potential impact if one device is compromised.
  • Regularly review and update passwords for all smart home and IoT devices.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVECybersecurityPatchSecurityThreatVulnerabilityzero-day

Share Article

David kimber

David kimber

David is a penetration tester turned security journalist with expertise in mobile security, IoT vulnerabilities, and exploit development. As an OSCP-certified security professional, David brings hands-on technical experience to his reporting on vulnerabilities and security research. His articles often feature detailed technical analysis of exploits and provide actionable defense recommendations. David maintains an active presence in the security research community and has contributed to multiple open-source security tools.

Previous Post

PAPERMILL Hackers Exploit Signed Notepad++ to Deploy VenomRAT in Tax Audits

Next Post

Critical Apache Syncope CVEs Let Attackers Execute Code, Bypass Controls

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Oracle Q3 2023 Critical Patch Update: 673 Vulnerabilities Fixed
September 16, 2026
Critical Issabel PBX RCE actively exploited, patch immediately
September 16, 2026
Critical HPE RMC, OneView, and iLO 5 Flaws Let Attackers Remotely Execute Code
September 16, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us