TL;DR
Get pool and patio gear delivered free — and shop member deals
- Fast, free delivery on millions of items
- Access to Prime Big Deal Days deals on October 6–7
- Prime Video, Amazon Music and more included
TP-Link has released firmware updates for its Tapo C200 and C120 cameras after OPSWAT researchers identified a login bypass that could give someone on the same network administrator access. A separate denial-of-service flaw affects the C200. Owners should install the latest firmware; remote exploitation without access to the local network is not described in the report.
TP-Link has issued firmware updates for its Tapo C200 and C120 cameras after security researchers found a login flaw that could let an attacker on the same network obtain administrator access without a password. The main flaw, tracked as CVE-2026-15315, could expose camera feeds, recordings and settings; a separate issue affecting the C200 could disrupt its service or restart the device.
Security firm OPSWAT reported two vulnerabilities in the Tapo C200 series. The more severe, CVE-2026-15315, is rated 8.7 and also affects the Tapo C120 in its V1 hardware version, according to TP-Link’s advisory. Researchers Khoi Tran and Thai Do found the issue in the cameras’ HTTPS management interface. Their report says an alternative verification path could treat a value supplied by the camera during login as a valid authentication response.
With a small number of requests, the flaw could create an administrator session without a password or existing session. An attacker who already had access to the same network could then reach live video and stored recordings or change camera settings. OPSWAT said the potential exposure could be especially sensitive when a camera is used as a baby monitor, citing live video, night vision, crying detection and two-way audio among the functions at risk.
The second vulnerability, CVE-2026-15316, has a severity score of 7.1 and affects the C200 alone. OPSWAT said oversized encrypted Wi-Fi credential data could crash the camera’s HTTPS service or cause the device to restart while recovering. TP-Link has issued firmware updates addressing both flaws. The C200 update addresses the login bypass and the service-disruption issue, while the C120 is listed as affected by the login bypass in its V1 hardware version. Owners need to install the latest firmware for their camera.
Risks for Cameras on Home Networks
The login bypass matters because an internet-connected camera can contain private video, audio and household information. If a device is reachable by someone already on the local network, the flaw could turn that network access into control of the camera without the owner’s password. The report does not say that an attacker can exploit this vulnerability from anywhere on the internet; it describes a prerequisite of being on the same Wi-Fi network or within a trusted ecosystem.
That limitation narrows the stated exposure, but does not make the issue irrelevant. A compromised or shared network can include devices and users the camera owner does not fully control. The separate C200 flaw presents a different risk: disruption to the camera’s service rather than the administrator access described for CVE-2026-15315. Applying the relevant firmware update addresses the issues identified by the report.
As an affiliate, we earn on qualifying purchases.
How the Two Flaws Differ
The report distinguishes a login bypass from a service-disruption vulnerability. CVE-2026-15315 concerns authentication in the HTTPS management interface and applies to the C200 and the C120’s V1 hardware version, according to TP-Link’s advisory. CVE-2026-15316 concerns oversized encrypted Wi-Fi credential data and is reported for the C200 only.
OPSWAT’s researchers disclosed the findings, and TP-Link has issued firmware updates for both camera models. The supplied report does not give firmware version numbers or release dates, so owners should use the update available for their specific model and hardware version rather than relying on a version number from another device.
““live video, night vision, crying detection and two-way audio””
— OPSWAT researchers Khoi Tran and Thai Do, as quoted in The Ambient’s report
As an affiliate, we earn on qualifying purchases.
Exploit Conditions and Patch Details
The available report does not state whether attackers have exploited either vulnerability, whether camera owners have been targeted, or how many devices may be affected. It also does not provide the firmware version numbers, a patch release timeline, or details about the update process for each hardware revision.
The reported attack path requires an attacker to be on the same Wi-Fi network or within a trusted ecosystem. The source does not explain how an attacker might gain that initial access, nor does it establish that the flaws can be used remotely over the public internet without a local-network foothold. TP-Link’s advisory is reported to list the C120’s V1 hardware version as affected by CVE-2026-15315; the supplied material does not identify other C120 revisions as affected.
home security camera with night vision
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
Install the Model-Specific Firmware
Tapo C200 and C120 owners should check for and install the latest firmware available for their camera, matching its model and hardware version. The update is the action identified by TP-Link to address the reported flaws. Owners should confirm the device has completed the update and check the camera’s software status afterward.
Further details, including the exact firmware versions and whether additional hardware revisions are affected, may depend on TP-Link’s current advisory and support information. The supplied report does not say whether the company plans further disclosures or whether OPSWAT has reported exploitation in the wild.
Wi-Fi security camera for baby monitor
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
Key Questions
Which TP-Link Tapo cameras are affected?
CVE-2026-15315 affects the Tapo C200 and, according to TP-Link’s advisory, the C120 in its V1 hardware version. The separate CVE-2026-15316 service-disruption flaw is reported to affect the C200 alone.
What could an attacker do with the login bypass?
OPSWAT researchers said an attacker on the same network could obtain administrator access without a password, potentially reaching live video, stored recordings and camera settings.
Can the flaws be exploited remotely from anywhere?
The report describes both attacks as requiring access to the same Wi-Fi network or a trusted ecosystem. It does not establish that an attacker can exploit them remotely over the public internet without first gaining that access.
What should camera owners do?
Install the latest firmware available for the specific camera model and hardware version. The report does not supply version numbers, so owners should check TP-Link’s current update information or the camera’s update settings.
Source: rss
Fall Picks
fall essentials
As an affiliate, we earn on qualifying purchases.
