Security researchers disclosed two critical zero-day flaws in TP-Link’s Tapo C200 security cameras, highlighting risks from local network access and a potential full compromise with an upcoming unspecified fix.
Security researchers have disclosed two zero-day flaws in TP-Link’s Tapo C200 security camera line, a model widely used for home monitoring, small-office security and baby or pet surveillance. According to Infosecurity Magazine and OPSWAT, one of the issues could let an attacker reach administrative functions and view live or recorded footage if they already have access to the local network. TP-Link said it had patched both problems in firmware version V5_1.4.6, released on 18 August.
The more serious issue, tracked as CVE-2026-15315, is an authentication-bypass weakness based on replay. OPSWAT says an attacker on the same network as the device could obtain a valid administrative session without knowing the password. That would permit changes to the camera’s settings and access to privileged controls. Dahvid Schloss, chief operating officer at Suzu Labs, told Infosecurity Magazine that the flaw is less alarming than it first appears because it still depends on local network access, although he noted that internet exposure through port forwarding would increase the risk.
The second flaw, CVE-2026-15316, affects the camera’s onboarding and configuration flow. TP-Link’s advisory says improperly validated encrypted input can cause crashes or restarts, creating a denial-of-service condition. OPSWAT said an unauthenticated attacker with network access could send an oversized encrypted value that would make the device’s HTTPS service fail. SecurityVulnerability.io’s analysis of the bug describes the same outcome: temporary disruption of management and monitoring functions until the service recovers.
OPSWAT also said it is working with TP-Link on a third vulnerability it has not yet published, which it classifies as critical. The firm said that issue could lead to full device compromise and allow an attacker to use the camera as a foothold inside the wider network. Schloss said such a chain would not be unusual in older consumer IoT equipment, but added that it would be notable if it were present in a modern TP-Link product.
Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.





