Popular TP-Link Tapo Cameras Patched To Prevent Unauthorised Local Access.
AIThis post was created with the assistance of artificial intelligence (AI).

TL;DR

Prime Big Deal Days · Oct 6–7Offer from Amazon

Get tools and workshop supplies delivered free — and shop member deals

  • Fast, free delivery on millions of items
  • Access to Prime Big Deal Days deals on October 6–7
  • Prime Video, Amazon Music and more included
Start your free Prime trial Free trial for eligible customers · Cancel anytime
As an affiliate, we earn on qualifying purchases.

TP-Link has released firmware updates for Tapo C200 and C120 cameras to address a high-severity authentication bypass that could give someone on the same network administrator access. A separate flaw that could crash or restart the C200 is also patched. The reported attacks require local network access; owners should install the latest firmware for each camera.

TP-Link has released firmware updates for its Tapo C200 and C120 cameras to fix a flaw that could let someone already on the same network gain administrator access without a password, according to a report by The Ambient. The updates also address a separate issue that could disrupt the C200’s HTTPS service or restart the device.

The more serious issue, tracked as CVE-2026-15315, has a severity score of 8.7 and affects the C200 series and the Tapo C120 V1 hardware version, according to TP-Link’s advisory as described by The Ambient. Security firm OPSWAT discovered the flaws. Its researchers, Khoi Tran and Thai Do, said the authentication weakness is in the cameras’ HTTPS management interface.

According to the researchers’ account, the interface has a second verification path that accepts a value supplied by the camera during login as an authentication response. A small number of requests can then produce an administrator session without a password or an existing session. That access could expose live video and stored recordings, and allow changes to camera settings. The reported scope is local: an attacker must already be on the same Wi-Fi network or within a trusted ecosystem.

A second issue, CVE-2026-15316, carries a score of 7.1 and affects the C200, according to the source report. It involves an oversized chunk of encrypted Wi-Fi credential data that can crash the HTTPS service or cause the camera to restart until it recovers. TP-Link has issued firmware updates addressing both flaws; the report advises owners to install the latest version on each affected camera.

At a glance
updateWhen: Firmware updates issued; the source rep…
The developmentTP-Link issued firmware updates for Tapo C200 and C120 cameras after researchers identified a local authentication bypass, along with a separate service-disruption flaw in the C200.

Camera Access Depends on Network Security

The login bypass matters because cameras can contain private footage and provide a view into household routines. If exploited by someone with access to a home network, the flaw could expose video or recordings and permit configuration changes. For households using a camera as a baby monitor, the potential exposure is especially personal: OPSWAT researchers said access could include live video, night vision, crying detection and two-way audio.

The local-access requirement limits the reported attack scenario. The source does not describe a remote internet attack that could reach any camera from anywhere; it says an attacker needs an existing foothold on the same network or in a trusted ecosystem. That constraint does not make the flaw irrelevant, but it means the reported risk depends in part on who can access the household network and whether the cameras have received the fix.

The separate C200 issue has a different effect. It is described as a way to interrupt the camera’s HTTPS service or trigger a restart, rather than as a route to view footage. Applying the update addresses both the access-control concern and that service-disruption vulnerability on affected hardware.

Amazon

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Two Flaws, Different Camera Impacts

The report distinguishes the vulnerabilities by both affected model and consequence. CVE-2026-15315 affects the C200 series and the C120 in its V1 hardware version, and concerns unauthorized administrator access. CVE-2026-15316 affects the C200 alone and concerns service crashes or device restarts. The supplied report does not give firmware version numbers or a date for the patches.

The findings are attributed to OPSWAT researchers, while the affected-device information and availability of updates are described with reference to TP-Link’s advisory. That distinction matters: the mechanism and potential consequences are researchers’ account of the vulnerabilities, while TP-Link’s advisory identifies affected hardware and the company’s firmware response. The available source says updates have been issued for both models and tells owners to install the latest version.

“The researchers said the authentication weakness can produce an administrator session after a small number of requests, without a password or an existing session.”

— OPSWAT researchers Khoi Tran and Thai Do, as reported by The Ambient

Amazon

Tapo C120 security camera

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Patch Versions and Exposure Remain Unclear

The source report does not specify the firmware version numbers, when the updates were released, or how many cameras may still be running vulnerable software. It also does not state whether attackers have exploited either flaw in real-world incidents. The reported requirement for same-network or trusted-ecosystem access narrows the described attack path, but the source does not explain how that access might be obtained.

The C120’s affected scope is identified specifically as V1 hardware; owners of other hardware revisions should check TP-Link’s advisory or device support information rather than assume that every revision is affected or unaffected. The supplied material also mentions an “unreported bug” in its framing, but provides no details to establish what that refers to. No additional conclusion about such a bug can be drawn from the information available.

Amazon

home security camera with local access control

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Owners Should Check Camera Firmware

Owners of Tapo C200 and C120 cameras should check for and install the latest firmware available for each device, following TP-Link’s update instructions. The C120’s hardware revision should be checked against the advisory because the report identifies V1 as affected. Updating the C200 addresses both vulnerabilities described in the report; updating an affected C120 addresses the login bypass.

Further details that would clarify the status include the exact patched firmware versions, the date each update became available, and whether TP-Link or researchers have received reports of exploitation. Until those details are available, the confirmed action is the company’s release of fixes and the recommendation that owners update affected cameras.

Amazon

Wi-Fi security camera with encrypted data

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Key Questions

The report names the Tapo C200 series and the Tapo C120 V1 hardware version for the authentication bypass, CVE-2026-15315. The separate CVE-2026-15316 service-disruption flaw is reported to affect the C200 alone.

What could someone do through the login bypass?

According to OPSWAT researchers, someone with the required local network access could obtain an administrator session without a password or existing session. That could expose live video and recordings and allow camera configuration changes.

Can the reported flaw be exploited remotely over the internet?

The source report says an attacker must already be on the same Wi-Fi network or within a trusted ecosystem. It does not describe an attack that can reach any camera remotely without that access.

What should camera owners do?

Install the latest firmware available for each affected camera, using TP-Link’s update process. C120 owners should verify their hardware revision against TP-Link’s advisory, which identifies V1 as affected.

Has exploitation of these flaws been confirmed?

The supplied report does not say whether either vulnerability has been exploited in real-world attacks. It describes the flaws and the firmware fixes, but provides no incident reports or exploitation confirmation.

Source: rss

FALL YARD WORK

Fall yard work Picks

As an affiliate, we earn on qualifying purchases.

You May Also Like

Elixir-lang.org Has A New Design

Elixir’s official website has launched a redesigned interface, aiming to improve user experience and accessibility, confirmed by the project team.

Kathleen V. Jameson Named Speed Museum Director

Kathleen V. Jameson has been named the new director of the Speed Art Museum, marking a significant leadership change in the institution.

Artists From 16 Countries Exhibit At Contemporary Istanbul

Artists from 16 nations are participating in the ongoing Contemporary Istanbul art fair, highlighting international collaboration and cultural exchange.

South Austin House Fire Ruled Accidental – KVUE

An investigation into a South Austin house fire concludes it was accidental, with authorities citing no evidence of foul play. Details remain under review.