TL;DR
Get tools and workshop supplies delivered free — and shop member deals
- Fast, free delivery on millions of items
- Access to Prime Big Deal Days deals on October 6–7
- Prime Video, Amazon Music and more included
TP-Link has released firmware updates for its Tapo C200 and C120 cameras after researchers reported vulnerabilities that could allow a person on the same network to gain administrator access. A separate flaw affecting the C200 could crash its HTTPS service or restart the device. Camera owners should install the latest firmware; the available report does not specify how many devices were affected or whether the flaws were exploited.
TP-Link has released firmware updates for its Tapo C200 and C120 cameras to fix vulnerabilities that could let someone on the same local network obtain administrator access, according to a report by The Ambient. Security researchers at OPSWAT also identified a separate flaw that could disrupt the C200’s HTTPS service or restart the camera.
The main issue, CVE-2026-15315, has a reported severity score of 8.7. The Ambient says it affects the C200 series and the Tapo C120 V1 hardware version, which TP-Link lists as affected in its advisory. Researchers Khoi Tran and Thai Do, from OPSWAT, found the problem in the cameras’ HTTPS management interface. A second verification path reportedly accepted a value supplied by the camera during login as an authentication response.
According to the report, an attacker could make a small number of requests to obtain an administrator session without a password or an existing session. That level of access could expose live video and stored recordings, and allow changes to camera settings. OPSWAT researchers also described potential access to features on a camera used as a baby monitor, including night vision, crying detection and two-way audio.
A second vulnerability, CVE-2026-15316, has a reported score of 7.1 and affects the C200 alone. The report says an oversized section of encrypted Wi-Fi credential data can cause the HTTPS service to crash or the camera to restart. TP-Link has issued updates addressing the reported flaws. Owners need to install the latest firmware on each affected camera; the source does not provide version numbers or detail the update process.
Local Network Access Could Expose Camera Feeds
The reported login bypass matters because administrator access could reveal private video and recordings or let an intruder alter camera settings. Cameras placed in living spaces or used to monitor children can capture sensitive activity, so an access flaw has consequences beyond a device’s ordinary settings.
The reported condition also limits the stated attack scenario: an attacker would need access to the same Wi-Fi network or another trusted part of the household’s network. That is different from a flaw that can be exploited by anyone over the internet, but it does not remove the risk for households with a compromised or shared network. The separate C200 issue presents a service disruption risk, rather than the administrator-access outcome described for CVE-2026-15315.
As an affiliate, we earn on qualifying purchases.
Two Vulnerabilities, Different Effects
The report identifies two distinct flaws in the camera software. CVE-2026-15315 is the authentication issue reported for C200 cameras and the C120’s V1 hardware. CVE-2026-15316 concerns oversized encrypted Wi-Fi credential data and is reported to affect the C200 alone. The identifiers and severity scores are given in the source report; detailed technical documentation beyond its account is not included in the supplied material.
Both reported attack paths require a person to be on the same Wi-Fi network or within a trusted ecosystem, according to The Ambient. OPSWAT is credited with discovering the issues, and the researchers named in the report are Khoi Tran and Thai Do. TP-Link’s response, as described there, is to provide firmware updates for the affected models.
““live video, night vision, crying detection and two-way audio””
— OPSWAT researchers Khoi Tran and Thai Do, as quoted in The Ambient report
As an affiliate, we earn on qualifying purchases.
Exploitation and Patch Versions Not Detailed
The available report does not say whether anyone exploited either flaw, how many cameras may be vulnerable, or how long the issues were present before they were discovered. It also does not give firmware version numbers, a precise patch release date, or instructions for confirming that an individual camera has been updated.
The source describes the attacks as requiring local network or trusted-ecosystem access, but it does not set out additional conditions or provide evidence about real-world attempts. The reported scope for the C120 is specifically V1 hardware; owners should check their device and TP-Link’s current support information rather than assume every C120 revision has the same status.
Wi-Fi security camera with night vision
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
Owners Should Install Current Firmware
Owners of Tapo C200 and C120 cameras should check TP-Link’s support or device-update tools for the latest firmware and apply it to each camera. The report says updates address the identified flaws but does not specify whether installation is automatic or whether a device restart is required. Users can check the camera’s model and hardware revision against TP-Link’s advisory, particularly for the C120 V1.
Further detail may come from TP-Link’s advisory or subsequent security disclosures, including exact firmware versions and any updated information about affected hardware. Until then, the confirmed action in the source material is to install the latest available update for each affected camera.
As an affiliate, we earn on qualifying purchases.
Key Questions
Which Tapo cameras are affected?
The report says CVE-2026-15315 affects the Tapo C200 series and the Tapo C120 V1 hardware version. The separate CVE-2026-15316 crash flaw is reported to affect the C200 alone.
What could an attacker do through the login flaw?
According to the report, someone on the same network could obtain an administrator session without a password or existing session, potentially accessing live video, recordings and camera settings.
Does the attack work from anywhere on the internet?
The described attack requires access to the same Wi-Fi network or a trusted ecosystem. The source does not describe it as an attack that can be carried out by any internet user.
What should camera owners do?
Install the latest available firmware on each affected camera and check the model and hardware revision against TP-Link’s advisory. The source report does not provide specific firmware version numbers.
Has TP-Link confirmed that the flaws were exploited?
The supplied report does not say whether either vulnerability has been exploited in the wild. That status remains unclear from the available information.
Source: rss
Fall Picks
fall essentials
As an affiliate, we earn on qualifying purchases.
