Security researchers have revealed two vulnerabilities in TP-Link’s Tapo C200 smart camera that could enable nearby network attackers to bypass administrator authentication or disrupt the device’s management service.
Khoi Tran and Thai Do from OPSWAT Unit 515 discovered these vulnerabilities, tracked as CVE-2026-15315 and CVE-2026-15316, during the company’s Critical Infrastructure Cybersecurity Graduate Fellowship Program. TP-Link addressed both issues in firmware version V5_1.4.6, which was released on August 18, 2026.
TP-Link Tapo Camera Flaw
The more critical vulnerability, CVE-2026-15315, is an authentication-bypass flaw in the camera’s local HTTPS management interface, which operates on port 443. The Tapo C200 uses a challenge-response process to verify a user’s knowledge of the administrator password before allowing an authenticated session.
However, researchers discovered an alternative verification method that incorrectly accepts a replayed value the camera originally returned during the authentication exchange.
As a result, an unauthenticated attacker with network access to the device can establish a valid administrative session without knowing, guessing, or recovering the camera’s password. Exploiting this vulnerability does not require user interaction, an existing authenticated session, or physical access to the camera.
Once an attacker establishes an administrative session, they can access privileged management functions and modify device settings. Depending on the available configuration options, this could jeopardize privacy-sensitive functions, including camera operation, live-stream access, and recorded footage.
This vulnerability highlights a recurring issue with embedded-device authentication: a challenge-response protocol is only secure if every possible verification path ensures proof of knowledge of the secret credential. Accepting a device-generated value as proof of authentication undermines this core requirement.

The second vulnerability, CVE-2026-15316, affects the camera’s Wi-Fi onboarding process. Researchers found that the affected firmware does not adequately validate the length of encrypted Wi-Fi credential data before it passes through cryptographic and configuration processing routines.
An attacker on the same network can submit an oversized encrypted credential value, triggering a crash in the camera’s HTTPS service. This denial-of-service condition could prevent legitimate administrators from accessing or managing the camera until the service recovers.
While this issue does not provide direct administrative access, it could affect the camera’s availability at critical moments, especially for cameras used in home monitoring, small-business surveillance, or other security operations.
TP-Link confirmed these vulnerabilities after OPSWAT reported them on April 16, 2026. CVE identifiers were assigned on August 13, followed by the vendor’s firmware release and advisory on August 18.
Users should promptly update their affected Tapo C200 devices to firmware version V5_1.4.6 or a later release. Administrators are also advised to avoid exposing camera management interfaces to untrusted networks, place IoT cameras on isolated VLANs where feasible, and restrict management access to authorized systems.
Additionally, OPSWAT stated that its researchers identified further issues during the assessment, including a potentially critical flaw related to camera compromise. The details of these findings remain under coordinated disclosure with TP-Link, and technical specifics have not yet been released.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

