TP-Link Tapo C120/C200: local auth bypass CVE-2026-15315 (CVSS 8.7) + C200 DoS CVE-2026-15316 (7.1)
TP-Link security advisory FAQ 5248 (last updated 27 August 2026; firmware release noted by OPSWAT as 18 August 2026) covers CVE-2026-15315 and CVE-2026-15316 in Tapo smart cameras. CVE-2026-15315 (CVSS v4.0 8.7 High; CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N): improper authentication in the login verification module on Tapo C120 V1 and C200 V5 — a local-network attacker can replay device_confirm challenge material to obtain administrative session tokens without the camera password. CVE-2026-15316 (CVSS v4.0 7.1 High; CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N): oversized encrypted Wi-Fi credential input in C200 V5 onboarding crashes/restarts the HTTPS management service (DoS). Discovery credit: OPSWAT Unit 515 / fellowship research (Khoi Tran, Thai Do); OPSWAT blog notes further critical findings still under coordinated disclosure. Adjacent-network only (AV:A) — not internet-unauth without LAN/VPN reach to the camera. SecurityWeek 18 Sep roundup re-amplified the advisory. Primary: TP-Link FAQ 5248; research: OPSWAT.
- Product
- TP-Link Tapo C120 (V1) and Tapo C200 (V5) smart cameras
- Versions
- C120 V1 before 1.9.3 Build 260521 (CVE-2026-15315); C200 V5 before V5_1.4.6 Build 260709 Rel.27675n (CVE-2026-15315 + CVE-2026-15316)
- CVSS
- (CVE-2026-15315 CVSS 4.0 High); 7.1 (CVE-2026-15316 CVSS 4.0 High) — TP-Link
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N (15315); CVSS:4.0 - Exploited in Australia?
- unknown
- Patch to
- Update Tapo C120 V1 to firmware 1.9.3 Build 260521 or later; update Tapo C200 V5 to V5_1.4.6 Build 260709 Rel.27675n or later (TP-Link FAQ 5248). Keep camera management off untrusted networks; do not expose HTTPS admin to the internet.
Primary: TP-Link — Security Advisory FAQ 5248 Tapo C120/C200 (updated 27 Aug 2026) · Vendor: TP-Link Support — FAQ 5248 / fixed firmware table · CVE: CVE-2026-15315, CVE-2026-15316 · OPSWAT — CVE-2026-15315/15316 research write-up
