TL;DR
Get home appliances delivered free — and shop member deals
- Fast, free delivery on millions of items
- Access to Prime Big Deal Days deals on October 6–7
- Prime Video, Amazon Music and more included
TP-Link has released firmware updates for its Tapo C200 and C120 cameras after researchers found a login bypass that could grant an attacker on the same network administrator access. A separate flaw could disrupt the C200’s HTTPS service or restart the device; owners need to install the latest firmware for their model.
Security firm OPSWAT identified two vulnerabilities in the Tapo C200 series. Its researchers, Khoi Tran and Thai Do, found that the more serious issue, CVE-2026-15315, also affects the Tapo C120 in hardware version V1, according to TP-Link’s advisory. It has a reported severity score of 8.7.
The login bypass is in the cameras’ HTTPS management interface. The researchers found a second verification path that accepts a value provided by the camera during login as an authentication response. According to the report, an attacker can use a small number of requests to obtain an administrator session without a password or an existing session. That access can expose live feeds and stored recordings and allow configuration changes.
A second vulnerability, CVE-2026-15316, is rated 7.1 and affects the C200 alone. The report says oversized encrypted Wi-Fi credential data can cause its HTTPS service to crash or the camera to restart while recovering. Both attacks require access to the same Wi-Fi network or another trusted part of the household’s network. TP-Link has released firmware updates for the affected models; owners need to install the latest version for each camera to address the reported flaws.
Risks for Cameras on Home Networks
The login bypass could give someone who already has access to a household network control over a camera that may capture private spaces. The possible exposure includes video, recordings and configuration, so the implications depend on where the camera is installed and what it monitors.
OPSWAT researchers said that when a camera is used as a baby monitor, an attacker could access live video, night vision, crying detection and two-way audio. That describes the capabilities potentially exposed by administrator access; it does not establish that any camera was accessed or that an attack occurred.
The same-network requirement limits who can exploit the flaws compared with an attack reachable from anywhere on the internet. It still matters for households with shared or compromised Wi-Fi, or other people and devices already admitted to a trusted network. Installing the firmware update closes the reported weaknesses on the affected camera.
Two Flaws, Different Camera Impact
The report distinguishes between the two vulnerabilities. CVE-2026-15315 is the authentication bypass affecting the C200 and, in V1 hardware, the C120. CVE-2026-15316 is a separate service disruption issue reported for the C200.
OPSWAT researchers disclosed the findings, and TP-Link’s advisory identifies affected hardware and firmware updates. The source report does not provide the firmware version numbers or an exact release date. The stated network access requirement is a key part of the risk: the reported attacks are not described as remotely exploitable by a person with no access to the local or trusted network.
“The Tapo C120 is listed as affected in its V1 hardware version.”
— The Ambient report, summarizing TP-Link’s advisory
Exposure and Update Status Unknown
The source material does not say whether attackers exploited either vulnerability, how many cameras may have been exposed, or whether TP-Link observed misuse. It also does not provide the affected firmware versions, update release dates or a detailed list of other hardware revisions.
The report says both issues require an attacker to be on the same Wi-Fi network or within a trusted ecosystem. It does not specify how the vulnerabilities might be combined with other weaknesses, or whether every owner has already received an update notification. Owners should check the firmware available for their own camera in TP-Link’s official update channel.
Owners Should Install Camera Updates
Tapo C200 and C120 owners should install the latest firmware available for their specific model and hardware version. The update addresses the login bypass, while the C200 update also addresses the reported HTTPS crash and restart issue. After updating, owners can check the camera’s firmware status in its management app or the manufacturer’s support information.
TP-Link’s advisory and any later notices may provide further detail on affected versions or update availability. The source report does not give a schedule for additional disclosures or say whether further firmware changes are planned.
Key Questions
Which Tapo cameras are affected by the login bypass?
The reported bypass, CVE-2026-15315, affects the Tapo C200 and the Tapo C120 in V1 hardware, according to TP-Link’s advisory as described in the source report.
What could an attacker access through the flaw?
According to the report, administrator access could expose live video, stored recordings and camera configuration. Researchers also described camera functions that could be exposed when a device is used as a baby monitor.
Does exploiting the flaw require internet access to the camera?
The reported attacks require access to the same Wi-Fi network or another trusted part of the household network. The source does not describe the flaws as exploitable by an unaffiliated attacker from anywhere on the internet.
What is the second vulnerability?
CVE-2026-15316, rated 7.1, affects the C200 alone. The report says oversized encrypted Wi-Fi credential data can crash its HTTPS service or cause the camera to restart while recovering.
What should owners do?
Install the latest firmware for the camera’s model and hardware version. TP-Link’s updates address the login bypass on the affected models and the separate service disruption issue on the C200.
Source: rss
Fall Picks
fall essentials
As an affiliate, we earn on qualifying purchases.
