Critical TP-Link Tapo Camera Vulnerabilities Let Attackers Spy on Users
Key Takeaways Two critical zero-day vulnerabilities (CVE-2026-15315 and CVE-2026-15316) were discovered in TP-Link Tapo C200 smart cameras. These flaws could enable an attacker on the same network to...
Key Takeaways
- Two critical zero-day vulnerabilities (CVE-2026-15315 and CVE-2026-15316) were discovered in TP-Link Tapo C200 smart cameras.
- These flaws could enable an attacker on the same network to bypass authentication for administrative access or trigger a denial-of-service condition.
- The vulnerabilities primarily affect the Tapo C200 model and were patched in firmware version V5_1.4.6, released on August 18, 2026.
- The issues were identified by OPSWAT researchers Khoi Tran and Thai Do.
Critical Flaws Expose TP-Link Tapo Cameras to Spying and Disruption
TP-Link Tapo C200 smart cameras, popular for their use in home and small business surveillance, were recently found to harbor two significant zero-day vulnerabilities. These security defects could allow threat actors operating on the same network to circumvent authentication mechanisms or incapacitate camera services, creating substantial privacy and operational risks for users.
Table Of Content
The identified flaws, officially cataloged as CVE-2026-15315 and CVE-2026-15316, have since been addressed by TP-Link. A crucial firmware update, version V5_1.4.6, rolled out on August 18, 2026, contains the necessary fixes. The widespread deployment of TP-Link Tapo cameras, which offer live video streaming, mobile app integration, and cloud functionalities, underscores the importance of these patches. While these network-connected features provide convenience, they also present potential entry points for adversaries if not properly secured.
The discovery of these vulnerabilities emerged from the diligent work of OPSWAT researchers Khoi Tran and Thai Do. Their findings were part of OPSWAT’s Critical Infrastructure Cybersecurity Graduate Fellowship Program. The research team meticulously analyzed the Tapo C200 firmware and its local communication protocols within a controlled lab environment to uncover these weaknesses.
Authentication Bypass: CVE-2026-15315
CVE-2026-15315 points to a severe authentication bypass vulnerability affecting the camera’s local HTTPS management interface. The Tapo C200 exposes its management service via HTTPS on port 443, employing a challenge-response mechanism to authenticate users before establishing a secure session. This system typically requires the device to issue a challenge, to which the client must respond with a value derived from the administrator’s password, confirming user legitimacy.
However, OPSWAT’s investigation revealed an alternative verification pathway within the affected camera that failed to adequately enforce password-based validation. This lapse meant that under specific circumstances, an attacker could reuse a value previously generated by the camera during an authentication attempt. The device would then erroneously accept this replayed value as valid, granting an administrative session without the attacker ever needing to know the actual camera password.
This vulnerability is particularly concerning because it enables a threat actor with network access to a vulnerable Tapo C200 to achieve administrator-level access with minimal effort. Critically, no valid account, pre-existing session, or user interaction is required for exploitation. Gaining administrative control could allow an attacker to modify device settings, reconfigure network parameters, access privileged management functions, and potentially view sensitive camera feeds or stored recordings. This capability poses a significant risk to privacy and could facilitate unauthorized surveillance.
Denial-of-Service Vulnerability: CVE-2026-15316
The second identified flaw, CVE-2026-15316, is a denial-of-service (DoS) vulnerability located within the camera’s Wi-Fi onboarding process. During this process, the device handles encrypted Wi-Fi credential data. OPSWAT discovered that the vulnerable firmware did not properly validate the size of this encrypted data before forwarding it to cryptographic and configuration-processing functions.
An unauthenticated attacker on the same network could exploit this by sending an excessively large encrypted credential value to the vulnerable service. This malformed input would cause the camera’s HTTPS service to crash, rendering the device inaccessible and unmanageable for legitimate users until the service eventually recovers. While authentication is not required, the attacker must possess network access to the camera, which could be via a local Wi-Fi network, a compromised internal system, or an improperly exposed management interface.
OPSWAT reported the vulnerabilities to TP-Link on April 16, 2026. TP-Link acknowledged the findings on July 10, assigned CVE-2026-15315 and CVE-2026-15316 on August 13, and subsequently released the necessary patches on August 18.
What You Should Do
- Immediately update all affected TP-Link Tapo C200 cameras to firmware version V5_1.4.6 or a later version.
- Restrict access to camera management interfaces to trusted internal networks only. Avoid exposing them directly to the internet.
- For businesses, segment IoT devices like smart cameras onto separate network segments or VLANs. This practice limits the potential impact if one device is compromised.
- Regularly review and update passwords for all smart home and IoT devices.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.