TL;DR
Get home appliances delivered free — and shop member deals
- Fast, free delivery on millions of items
- Access to Prime Big Deal Days deals on October 6–7
- Prime Video, Amazon Music and more included
TP-Link has issued firmware updates for its Tapo C200 and C120 cameras after security researchers found a login flaw that could give someone on the same network administrator access. A separate vulnerability could crash or restart the C200. The attacks require access to the household’s network, and owners need to install the latest firmware for their models.
TP-Link has released firmware updates for its Tapo C200 and C120 cameras after researchers found a flaw that could let an attacker on the same network gain administrator access without a password. A second flaw affecting the C200 could disrupt its HTTPS service or restart the device; TP-Link’s updates address both vulnerabilities, according to the source report.
Researchers Khoi Tran and Thai Do of security firm OPSWAT identified the login bypass, tracked as CVE-2026-15315. The vulnerability has a reported severity score of 8.7 and affects the C200 series and the C120 in its V1 hardware version, according to the report and TP-Link’s advisory.
The issue is in the cameras’ HTTPS management interface. OPSWAT’s researchers found an alternate verification path that accepts a value provided by the camera during login as an authentication response. A small number of requests can then produce an administrator session, the report says, without requiring a password or an existing session. The access could expose live video and stored recordings and allow configuration changes.
A second vulnerability, CVE-2026-15316, has a reported score of 7.1 and affects the C200 alone. The report says that sending an oversized portion of encrypted Wi-Fi credential data can crash the HTTPS service or cause the camera to restart while it recovers. TP-Link has released updates for both models addressing the listed flaws. Owners must install the latest firmware on each camera, the report advises.
Network Access Could Expose Camera Feeds
The login bypass matters because administrator access can reach more than a camera’s basic status information. According to the report, an attacker who exploits it could view live footage and saved recordings or change device settings. For households using a camera as a baby monitor, the potential exposure may also include features such as night vision and two-way audio.
The reported attack condition narrows the risk: an attacker must already be on the same Wi-Fi network or inside a trusted ecosystem. That does not mean the flaw is harmless; it means the vulnerability is not described as a remote attack available to anyone on the internet. Installing the firmware update is the stated way to address the vulnerabilities on affected cameras.
As an affiliate, we earn on qualifying purchases.
Two Flaws Affect Different Models
The report describes two separate vulnerabilities, with different effects and device coverage. CVE-2026-15315 is the authentication bypass affecting the C200 and, in V1 hardware, the C120. CVE-2026-15316 is a denial-of-service issue affecting the C200 alone. The source material identifies OPSWAT as the discoverer and names researchers Khoi Tran and Thai Do.
Both flaws require the attacker to have access to the same network or a trusted ecosystem, according to the report. The supplied information does not give firmware version numbers, release dates or a count of affected devices. It says TP-Link issued updates and directs owners to install the latest firmware for their cameras.
“live video, night vision, crying detection and two-way audio”
— OPSWAT researchers Khoi Tran and Thai Do, as quoted in The Ambient report
security camera with local network access
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
Firmware Versions and Exposure Details
The source report does not provide the exact firmware version numbers, the dates the updates became available, or details of how owners are notified. It also does not say whether TP-Link has confirmed that either flaw was exploited in real-world attacks or how many cameras may have been exposed.
The C120 is listed as affected in its V1 hardware version, but the supplied information does not clarify whether other hardware revisions were assessed. The report also mentions an unreported bug in its headline but does not provide details about a separate, undisclosed issue; its specific vulnerability descriptions concern the two CVEs above.
home security camera with night vision
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
Owners Should Check Camera Firmware
Owners of Tapo C200 and C120 cameras should check each device for the latest available firmware and install the update, following TP-Link’s instructions. C200 owners should take particular note that the update addresses both the login bypass and the separate service-crash flaw; C120 owners should verify that their hardware version is covered.
The report does not identify a later investigation milestone or give a timetable for further updates. Any additional details from TP-Link about affected firmware releases, other hardware versions or confirmed exploitation would clarify the remaining questions.
smart home camera with two-way audio
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
Key Questions
Which TP-Link Tapo cameras are affected?
The login bypass, CVE-2026-15315, affects the Tapo C200 series and the C120 in its V1 hardware version. The separate CVE-2026-15316 crash flaw affects the C200 alone, according to the report.
What could an attacker do with the login bypass?
According to the report, an attacker who gains administrator access could view live video and stored recordings and change camera settings. The flaw requires the attacker to be on the same network or within a trusted ecosystem.
Does the vulnerability let anyone attack the camera over the internet?
The source report says both attacks require access to the same Wi-Fi network or a trusted ecosystem. It does not describe them as attacks that can be launched by anyone on the internet without that access.
How can owners address the flaws?
TP-Link has issued firmware updates for the affected models. Owners should install the latest firmware on each camera and check TP-Link’s instructions for model and hardware-version details.
Source: rss
Fall yard work Picks
leaf blowers
As an affiliate, we earn on qualifying purchases.
