Researchers uncover critical flaws in TP-Link’s Tapo C200 smart camera, enabling potential unauthorised access and device disruption; users advised to update firmware immediately.
Security researchers have identified two vulnerabilities in TP-Link’s Tapo C200 smart camera that could allow an attacker on the same network to take control of the device or disrupt its operation. According to Opswat, one flaw permits authentication bypass, while the other can trigger a denial-of-service condition. TP-Link has since issued firmware V5_1.4.6, and users are being urged to install it without delay.
The more serious issue is tracked as CVE-2026-15315. TP-Link’s own security notice describes it as an unauthorised administrative authentication bypass affecting the Tapo C120 and C200 models. In practical terms, a successful exploit could let an attacker obtain an administrative session without knowing the password, which would expose camera controls and potentially the live video feed. Opswat assigned the flaw a severity score of 8.7 out of 10.
The second vulnerability, CVE-2026-15316, affects the camera’s configuration service. TP-Link says it involves oversized encrypted credential input, while independent CVE records describe it as improper input validation. If exploited, the flaw can cause the device to crash or restart, briefly interrupting HTTPS management and monitoring. The issue was rated 7.1 out of 10 by Opswat, placing it in the high-severity category.
TP-Link says it was notified of the bugs in mid-April and began work on a fix in early July before releasing the patched firmware on 18 August 2026. The company’s download page lists V5_1.4.6 Build 260709 as the corrective release for the Tapo C200 v5. The company also says the same update addresses the Tapo C120. The vulnerabilities matter because the Tapo line is widely used in homes and small businesses, with TP-Link saying the app has more than 13 million users and the Google Play Store showing more than 10 million downloads.
Although there is no public evidence that the flaws have been exploited in the wild, the exposure is still significant because smart cameras sit at the edge of private networks and are often left running continuously. Security analysts quoted by TechRadar noted that the attack requires local network access, which limits the threat in many home set-ups, but also said any internet-exposed device should be treated as a higher-risk case. For most users, the immediate priority is straightforward: update the camera firmware and confirm the device is not unnecessarily reachable from outside the home network.
Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.





