Global Edition
Global Edition
UK Edition
EU Edition
US Edition

Understand the story, not the spin.

Markets

TP-Link Tapo Camera Flaws Patched, Critical Vulnerability Pending

Published 20 September 2026

Security researchers have disclosed two vulnerabilities in TP-Link Tapo C200 smart cameras that could allow attackers to bypass authentication or disrupt device operations, with a firmware patch now available. The flaws, discovered by OPSWAT, were addressed in an update released in August 2026, but a third critical vulnerability remains under coordinated disclosure with the manufacturer. The first vulnerability, tracked as CVE-2026-15315, is an authentication bypass flaw in the camera's local HTTPS management interface. Researchers found that an alternative verification method incorrectly accepts a replayed value, enabling an attacker with local network access to establish a valid administrative session without a password. This could grant unauthorized access to camera settings, live video streams, and stored recordings. The second flaw, CVE-2026-15316, is a denial-of-service vulnerability affecting the WiFi onboarding process. An attacker can submit oversized encrypted credential data, triggering a crash in the camera's HTTPS service and temporarily disabling management and monitoring functions. TP-Link patched both vulnerabilities in firmware version V5.1.4.

0:00 / 0:00