Popular TP-Link Tapo cameras patched to prevent unauthorised local access.

TP-Link has patched a login flaw in its Tapo C200 and C120 cameras that gave anyone on the same network admin access.

Security firm OPSWAT discovered the security flaws, and its researchers detailed two high-severity flaws in the Tapo C200 series.

The more serious flaw, CVE-2026-15315, carries a score of 8.7 and also reaches a second camera model, the Tapo C120, which TP-Link’s advisory lists as affected in its V1 hardware version.

How the login bypass works

The flaw sits in the management interface both cameras run over HTTPS, where OPSWAT researchers Khoi Tran and Thai Do found a second verification path that accepts a value the camera hands out during login as an authentication response.

The result is an administrator session after a small number of requests, with no password or existing session needed, which opens live video, stored recordings, and configuration changes to anyone on the same network.

That access carries higher stakes when the camera doubles as a baby monitor, which OPSWAT’s researchers say would expose “live video, night vision, crying detection and two-way audio” to an attacker.

Alongside that bypass, CVE-2026-15316 scores 7.1 and affects the C200 alone, where an oversized chunk of encrypted Wi-Fi credential data can crash the HTTPS service or restart the device until it recovers.

Both attacks need the attacker to sit on the same Wi-Fi network or within a trusted ecosystem first, which restricts the risk to people who already hold some access to a household’s network.

Patches and an unreported bug

TP-Link has issued firmware updates for both models that address CVE-2026-15315 and CVE-2026-15316, and owners must install the latest version on each camera to close the login bypass and, for the C200, the crash bug.

Minha Loja Teresa
We will be happy to hear your thoughts

Leave a reply

My Teresa Store
Logo
Shopping cart