Popular TP-Link Tapo Cameras Patched To Prevent Unauthorised Local Access.
AIThis post was created with the assistance of artificial intelligence (AI).

TL;DR

Prime Big Deal Days · Oct 6–7Offer from Amazon

Get home appliances delivered free — and shop member deals

  • Fast, free delivery on millions of items
  • Access to Prime Big Deal Days deals on October 6–7
  • Prime Video, Amazon Music and more included
Start your free Prime trial Free trial for eligible customers · Cancel anytime
As an affiliate, we earn on qualifying purchases.

TP-Link has issued firmware updates for its Tapo C200 and C120 cameras after security researchers found a login flaw that could give someone on the same network administrator access. A separate vulnerability could crash or restart the C200. The attacks require access to the household’s network, and owners need to install the latest firmware for their models.

TP-Link has released firmware updates for its Tapo C200 and C120 cameras after researchers found a flaw that could let an attacker on the same network gain administrator access without a password. A second flaw affecting the C200 could disrupt its HTTPS service or restart the device; TP-Link’s updates address both vulnerabilities, according to the source report.

Researchers Khoi Tran and Thai Do of security firm OPSWAT identified the login bypass, tracked as CVE-2026-15315. The vulnerability has a reported severity score of 8.7 and affects the C200 series and the C120 in its V1 hardware version, according to the report and TP-Link’s advisory.

The issue is in the cameras’ HTTPS management interface. OPSWAT’s researchers found an alternate verification path that accepts a value provided by the camera during login as an authentication response. A small number of requests can then produce an administrator session, the report says, without requiring a password or an existing session. The access could expose live video and stored recordings and allow configuration changes.

A second vulnerability, CVE-2026-15316, has a reported score of 7.1 and affects the C200 alone. The report says that sending an oversized portion of encrypted Wi-Fi credential data can crash the HTTPS service or cause the camera to restart while it recovers. TP-Link has released updates for both models addressing the listed flaws. Owners must install the latest firmware on each camera, the report advises.

At a glance
updateWhen: Firmware updates issued; the source rep…
The developmentTP-Link released firmware updates addressing two security flaws in Tapo C200 cameras and a login bypass that also affects the Tapo C120.

Network Access Could Expose Camera Feeds

The login bypass matters because administrator access can reach more than a camera’s basic status information. According to the report, an attacker who exploits it could view live footage and saved recordings or change device settings. For households using a camera as a baby monitor, the potential exposure may also include features such as night vision and two-way audio.

The reported attack condition narrows the risk: an attacker must already be on the same Wi-Fi network or inside a trusted ecosystem. That does not mean the flaw is harmless; it means the vulnerability is not described as a remote attack available to anyone on the internet. Installing the firmware update is the stated way to address the vulnerabilities on affected cameras.

Amazon

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Two Flaws Affect Different Models

The report describes two separate vulnerabilities, with different effects and device coverage. CVE-2026-15315 is the authentication bypass affecting the C200 and, in V1 hardware, the C120. CVE-2026-15316 is a denial-of-service issue affecting the C200 alone. The source material identifies OPSWAT as the discoverer and names researchers Khoi Tran and Thai Do.

Both flaws require the attacker to have access to the same network or a trusted ecosystem, according to the report. The supplied information does not give firmware version numbers, release dates or a count of affected devices. It says TP-Link issued updates and directs owners to install the latest firmware for their cameras.

“live video, night vision, crying detection and two-way audio”

— OPSWAT researchers Khoi Tran and Thai Do, as quoted in The Ambient report

Amazon

security camera with local network access

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Firmware Versions and Exposure Details

The source report does not provide the exact firmware version numbers, the dates the updates became available, or details of how owners are notified. It also does not say whether TP-Link has confirmed that either flaw was exploited in real-world attacks or how many cameras may have been exposed.

The C120 is listed as affected in its V1 hardware version, but the supplied information does not clarify whether other hardware revisions were assessed. The report also mentions an unreported bug in its headline but does not provide details about a separate, undisclosed issue; its specific vulnerability descriptions concern the two CVEs above.

Amazon

home security camera with night vision

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Owners Should Check Camera Firmware

Owners of Tapo C200 and C120 cameras should check each device for the latest available firmware and install the update, following TP-Link’s instructions. C200 owners should take particular note that the update addresses both the login bypass and the separate service-crash flaw; C120 owners should verify that their hardware version is covered.

The report does not identify a later investigation milestone or give a timetable for further updates. Any additional details from TP-Link about affected firmware releases, other hardware versions or confirmed exploitation would clarify the remaining questions.

Amazon

smart home camera with two-way audio

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Key Questions

The login bypass, CVE-2026-15315, affects the Tapo C200 series and the C120 in its V1 hardware version. The separate CVE-2026-15316 crash flaw affects the C200 alone, according to the report.

What could an attacker do with the login bypass?

According to the report, an attacker who gains administrator access could view live video and stored recordings and change camera settings. The flaw requires the attacker to be on the same network or within a trusted ecosystem.

Does the vulnerability let anyone attack the camera over the internet?

The source report says both attacks require access to the same Wi-Fi network or a trusted ecosystem. It does not describe them as attacks that can be launched by anyone on the internet without that access.

How can owners address the flaws?

TP-Link has issued firmware updates for the affected models. Owners should install the latest firmware on each camera and check TP-Link’s instructions for model and hardware-version details.

Source: rss

FALL YARD WORK

Fall yard work Picks

As an affiliate, we earn on qualifying purchases.

You May Also Like

Bissell TurboClean Review: Pros, Cons, and Who It’s For

An in-depth review of the Bissell TurboClean, highlighting its strengths, weaknesses, and ideal users. Find out if this lightweight carpet cleaner suits your needs.

Planning In Place For 80,000 Dublin Homes, But Work Has Started On Less Than Half – The Irish Times

Plans exist for 80,000 Dublin homes, but actual construction has begun on fewer than 40,000. The situation raises questions about housing supply and planning delays.

Jerusalem Apartment Deal Hits Record 15M Shekels As Buyers Combine Three Units Into One – Calcalistech.com

Buyers in Jerusalem pay a record 15 million shekels for a combined three-unit apartment, setting a new high in the local real estate market.

Genf: Solvalor 61 Kauft Wohnhaus – IMMOBILIEN Business

Solvalor 61 has purchased a residential property in Geneva, marking a significant move in the local real estate market. Details on the deal and implications follow.