AIThis post was created with the assistance of artificial intelligence (AI).

TL;DR

Prime Big Deal Days · Oct 6–7Offer from Amazon

Get your home office setup delivered free — and shop member deals

  • Fast, free delivery on millions of items
  • Access to Prime Big Deal Days deals on October 6–7
  • Prime Video, Amazon Music and more included
Start your free Prime trial Free trial for eligible customers · Cancel anytime
As an affiliate, we earn on qualifying purchases.

TP-Link has released firmware updates for its Tapo C200 and C120 cameras after security researchers found a login bypass that could give an attacker on the same network administrator access. A separate flaw could crash or restart the C200. Owners should install the latest firmware; the reported attacks require prior access to the camera’s local network.

TP-Link has patched two security flaws in its Tapo C200 and C120 cameras, including a login bypass that researchers say could let someone already on the same network obtain administrator access without a password. The updates address a vulnerability affecting both models and a separate service-crash flaw in the C200.

Security firm OPSWAT found the vulnerabilities and published details of two flaws in the Tapo C200 series. Its researchers, Khoi Tran and Thai Do, identified the more serious issue as CVE-2026-15315, rated 8.7. TP-Link’s advisory lists the Tapo C120 V1 hardware version as affected by that flaw as well as the C200.

The bypass is in the cameras’ HTTPS management interface. According to OPSWAT’s findings, a second verification path treats a value supplied by the camera during login as an authentication response. A small number of requests can then produce an administrator session without a password or an existing authenticated session. The source report says that access could expose live video and stored recordings and allow configuration changes.

A second vulnerability, CVE-2026-15316, has a reported score of 7.1 and affects the C200 alone. OPSWAT says an oversized chunk of encrypted Wi-Fi credential data can crash the HTTPS service or restart the camera until it recovers. TP-Link has issued firmware updates addressing both vulnerabilities. Owners need to install the latest available firmware on each camera; the C200 update addresses both flaws, while the C120 is listed as affected by the login bypass.

At a glance
updateWhen: Firmware updates released; the source r…
The developmentTP-Link issued firmware updates for Tapo C200 and C120 cameras to address a high-severity local authentication bypass and a separate C200 crash vulnerability.

Local Network Access Has Real Privacy Risks

The findings matter because these are home cameras that can capture private spaces. If an attacker has already gained access to the household’s Wi-Fi or another trusted part of the local network, the login bypass could extend that access to camera feeds, recordings and settings. That creates a privacy risk beyond the initial compromise of the network.

OPSWAT’s researchers highlighted the added sensitivity when a camera is used as a baby monitor. They said an attacker could access live video, night vision, crying detection and two-way audio. Those capabilities are described by the researchers as possible consequences of administrator access; the source report does not say that cameras have been exploited in real-world attacks.

The reported network requirement narrows the circumstances for an attack: the attacker must already be on the same Wi-Fi network or within a trusted ecosystem. That is not the same as a flaw that can be reached by anyone over the internet, but it can still matter in households with shared networks, compromised devices or guests who retain access. Applying the firmware update removes the affected software weakness, but it does not by itself resolve any separate problem that may have allowed an attacker onto the network.

Amazon

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Two Flaws, With Different Affected Models

The vulnerabilities have different reach and effects. CVE-2026-15315 is the authentication bypass reported in both the C200 and the C120 V1. CVE-2026-15316 is a denial-of-service-style issue reported only in the C200, where crafted or oversized encrypted Wi-Fi credential data can disrupt the HTTPS service or prompt a restart.

The source report describes both attacks as requiring a foothold on the local network or within a trusted ecosystem. It does not describe either issue as an internet-wide attack, nor does it provide evidence that the flaws have been used against camera owners. TP-Link’s firmware releases are the available fix identified in the report, so model owners should check that each camera is running the latest version rather than assuming an update to one device covers another.

“The authentication path can create an administrator session after a small number of requests, without a password or existing session.”

— OPSWAT researchers Khoi Tran and Thai Do, as reported by The Ambient

Amazon

home security camera with privacy features

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Exploit Activity and Update Coverage

The report does not say whether anyone has exploited the vulnerabilities, how many devices may be exposed, or whether attackers have used the flaws outside research. It also does not provide the firmware version numbers, rollout dates, or instructions for checking the installed version on each model.

TP-Link’s advisory is reported to list the C120’s V1 hardware version as affected by CVE-2026-15315. The available source material does not establish whether other C120 hardware revisions are affected, or provide a complete list of firmware versions that contain the fixes. The C200 is described as affected by both vulnerabilities, while the C120 is identified in connection with the login bypass.

Amazon

Wi-Fi security camera with local network access

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Owners Should Check Camera Firmware

Tapo C200 and C120 owners should use TP-Link’s official support materials or the camera’s management tools to check for and install the latest firmware for their specific model and hardware revision. The update should be applied to each camera separately, and owners should confirm that installation has completed rather than relying on an update to another device on the network.

Further details that would help owners include the precise fixed firmware versions, the full hardware-revision coverage for each model and any later information from TP-Link or OPSWAT about exploitation. Until that information is available, the confirmed action is to update affected cameras and limit local-network access to trusted devices and users.

Amazon

smart home security camera

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Key Questions

The Tapo C200 is affected by both reported flaws. TP-Link’s advisory lists the Tapo C120 V1 as affected by the login bypass, CVE-2026-15315. The source report does not establish whether other C120 hardware revisions are affected.

What could an attacker do with the login bypass?

OPSWAT says someone on the same network could obtain administrator access without a password, potentially reaching live video and stored recordings and changing camera settings.

Can the vulnerabilities be exploited from anywhere on the internet?

The source report says the attacks require the attacker to be on the same Wi-Fi network or within a trusted ecosystem. It does not describe them as remotely exploitable by anyone on the internet.

What should camera owners do?

Install the latest firmware available for each camera, checking the model and hardware revision against TP-Link’s official support information. The report does not provide fixed firmware version numbers.

Is there evidence that the flaws have been used in attacks?

The available report does not say whether the vulnerabilities have been exploited in real-world attacks. That status remains unclear.

Source: rss

FALL

Fall Picks

As an affiliate, we earn on qualifying purchases.

You May Also Like

How to Replace a Damaged Lens Cap or Cover

Theoretically, replacing a damaged lens cap is simple, but essential steps ensure your lens stays protected—continue reading to learn how.

Bulb Replacement Troubleshooting: Resetting Lamp Timers and Avoiding Errors

Keen to ensure your projector’s lamp functions correctly? Discover essential troubleshooting tips to reset timers and prevent error messages efficiently.

The Troubleshooting Kit Every Projector Owner Should Have

Master your projector maintenance with this essential troubleshooting kit—discover why having these tools can save you time and money.

Blurry Projector Image: How to Sharpen Focus and Adjust Lens

I’ll guide you through simple steps to sharpen your blurry projector image and improve your viewing experience.