Popular TP-Link Tapo Cameras Patched To Prevent Unauthorised Local Access.
AIThis post was created with the assistance of artificial intelligence (AI).

TL;DR

Prime Big Deal Days · Oct 6–7Offer from Amazon

Get pool and patio gear delivered free — and shop member deals

  • Fast, free delivery on millions of items
  • Access to Prime Big Deal Days deals on October 6–7
  • Prime Video, Amazon Music and more included
Start your free Prime trial Free trial for eligible customers · Cancel anytime
As an affiliate, we earn on qualifying purchases.

TP-Link has released firmware updates for its Tapo C200 and C120 cameras after OPSWAT researchers identified a login bypass that could give someone on the same network administrator access. A separate denial-of-service flaw affects the C200. Owners should install the latest firmware; remote exploitation without access to the local network is not described in the report.

TP-Link has issued firmware updates for its Tapo C200 and C120 cameras after security researchers found a login flaw that could let an attacker on the same network obtain administrator access without a password. The main flaw, tracked as CVE-2026-15315, could expose camera feeds, recordings and settings; a separate issue affecting the C200 could disrupt its service or restart the device.

Security firm OPSWAT reported two vulnerabilities in the Tapo C200 series. The more severe, CVE-2026-15315, is rated 8.7 and also affects the Tapo C120 in its V1 hardware version, according to TP-Link’s advisory. Researchers Khoi Tran and Thai Do found the issue in the cameras’ HTTPS management interface. Their report says an alternative verification path could treat a value supplied by the camera during login as a valid authentication response.

With a small number of requests, the flaw could create an administrator session without a password or existing session. An attacker who already had access to the same network could then reach live video and stored recordings or change camera settings. OPSWAT said the potential exposure could be especially sensitive when a camera is used as a baby monitor, citing live video, night vision, crying detection and two-way audio among the functions at risk.

The second vulnerability, CVE-2026-15316, has a severity score of 7.1 and affects the C200 alone. OPSWAT said oversized encrypted Wi-Fi credential data could crash the camera’s HTTPS service or cause the device to restart while recovering. TP-Link has issued firmware updates addressing both flaws. The C200 update addresses the login bypass and the service-disruption issue, while the C120 is listed as affected by the login bypass in its V1 hardware version. Owners need to install the latest firmware for their camera.

At a glance
updateWhen: Firmware updates issued; the source rep…
The developmentTP-Link issued firmware updates for Tapo C200 and C120 cameras to address a high-severity login bypass and a separate C200 service-disruption flaw.

Risks for Cameras on Home Networks

The login bypass matters because an internet-connected camera can contain private video, audio and household information. If a device is reachable by someone already on the local network, the flaw could turn that network access into control of the camera without the owner’s password. The report does not say that an attacker can exploit this vulnerability from anywhere on the internet; it describes a prerequisite of being on the same Wi-Fi network or within a trusted ecosystem.

That limitation narrows the stated exposure, but does not make the issue irrelevant. A compromised or shared network can include devices and users the camera owner does not fully control. The separate C200 flaw presents a different risk: disruption to the camera’s service rather than the administrator access described for CVE-2026-15315. Applying the relevant firmware update addresses the issues identified by the report.

Amazon

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

How the Two Flaws Differ

The report distinguishes a login bypass from a service-disruption vulnerability. CVE-2026-15315 concerns authentication in the HTTPS management interface and applies to the C200 and the C120’s V1 hardware version, according to TP-Link’s advisory. CVE-2026-15316 concerns oversized encrypted Wi-Fi credential data and is reported for the C200 only.

OPSWAT’s researchers disclosed the findings, and TP-Link has issued firmware updates for both camera models. The supplied report does not give firmware version numbers or release dates, so owners should use the update available for their specific model and hardware version rather than relying on a version number from another device.

““live video, night vision, crying detection and two-way audio””

— OPSWAT researchers Khoi Tran and Thai Do, as quoted in The Ambient’s report

Amazon

Tapo C120 security camera

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Exploit Conditions and Patch Details

The available report does not state whether attackers have exploited either vulnerability, whether camera owners have been targeted, or how many devices may be affected. It also does not provide the firmware version numbers, a patch release timeline, or details about the update process for each hardware revision.

The reported attack path requires an attacker to be on the same Wi-Fi network or within a trusted ecosystem. The source does not explain how an attacker might gain that initial access, nor does it establish that the flaws can be used remotely over the public internet without a local-network foothold. TP-Link’s advisory is reported to list the C120’s V1 hardware version as affected by CVE-2026-15315; the supplied material does not identify other C120 revisions as affected.

Amazon

home security camera with night vision

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Install the Model-Specific Firmware

Tapo C200 and C120 owners should check for and install the latest firmware available for their camera, matching its model and hardware version. The update is the action identified by TP-Link to address the reported flaws. Owners should confirm the device has completed the update and check the camera’s software status afterward.

Further details, including the exact firmware versions and whether additional hardware revisions are affected, may depend on TP-Link’s current advisory and support information. The supplied report does not say whether the company plans further disclosures or whether OPSWAT has reported exploitation in the wild.

Amazon

Wi-Fi security camera for baby monitor

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Key Questions

CVE-2026-15315 affects the Tapo C200 and, according to TP-Link’s advisory, the C120 in its V1 hardware version. The separate CVE-2026-15316 service-disruption flaw is reported to affect the C200 alone.

What could an attacker do with the login bypass?

OPSWAT researchers said an attacker on the same network could obtain administrator access without a password, potentially reaching live video, stored recordings and camera settings.

Can the flaws be exploited remotely from anywhere?

The report describes both attacks as requiring access to the same Wi-Fi network or a trusted ecosystem. It does not establish that an attacker can exploit them remotely over the public internet without first gaining that access.

What should camera owners do?

Install the latest firmware available for the specific camera model and hardware version. The report does not supply version numbers, so owners should check TP-Link’s current update information or the camera’s update settings.

Source: rss

FALL

Fall Picks

As an affiliate, we earn on qualifying purchases.

You May Also Like

Host Effortless Poolside Parties with the Ninja SLUSHi XL Frozen Drink Maker

Make your summer pool parties unforgettable with the Ninja SLUSHi XL, offering large capacity, versatile drinks, and easy cleanup for stress-free hosting.

Ninja BN805A Pro Plus Kitchen System: Your Summer Blend Buddy

Explore the Ninja BN805A Pro Plus Kitchen System — a powerful, versatile blender perfect for summer smoothies, frozen drinks, and more.

This Designer’s 70-20-10 Rule Makes Cheap Furniture Look Expensive

A designer’s 70-20-10 rule is gaining attention for making inexpensive furniture appear high-end, sparking increased interest in affordable interior design strategies.

Their Dining Room Furniture Looked Dated Until 1 DIY Changed The Whole Room

Chelsea and Jason Scott spent about $370 on faux board and batten, new curtains and a pendant to update their beige Ohio dining room.