Vulnerabilities · 6h ago

TP-Link Tapo C200 Replay Flaw Exposed Admin Access

OPSWAT disclosed two zero-days in the TP-Link Tapo C200 camera and said TP-Link shipped firmware V5_1.4.6 on Aug. 18 to fix them. One of the flaws, CVE-2026-15315, is an authentication-replay bypass that can give a network-accessible attacker a valid administrative session without the password.

With that session, the camera treats the attacker like the owner: they can change settings and reach privacy-sensitive functions such as live video and stored recordings. The second bug, CVE-2026-15316, is a denial-of-service issue in the onboarding flow that can crash the camera's HTTPS service when fed oversized encrypted credential data.

For home, baby/pet, and small-office setups, the lasting exposure is not just a failed login screen. If the camera sits on a reachable LAN, or worse is port-forwarded, a replay bug can turn a common monitor into a persistent surveillance point until the firmware is updated.

CVE-2026-15315

NVD KEV

CVSS 8.8 HIGH: tapo C120 v1 and C200 v5 contain an improper authentication vulnerability within the login authentication verification module. EPSS 0.3% (22nd percentile).

CVE-2026-15316

NVD KEV

CVSS 6.5 MEDIUM: an improper input validation vulnerability in the configuration service for processing encrypted credential data has… EPSS 0.2% (13th percentile).

Timeline

Sources

1 source covering this story

Entities

Part of the PlainSec briefing for 2026-09-16

Editions

Related stories