Severity
High
Analysis Summary
TP-Link Tapo C200 smart cameras were affected by two zero-day vulnerabilities, tracked as CVE-2026-15315 and CVE-2026-15316, which could allow attackers with network access to bypass authentication or disrupt camera services. The vulnerabilities were discovered by OPSWAT researchers through analysis of the Tapo C200 firmware and local communication functions in a controlled laboratory environment. Tapo C200 cameras are widely used in homes and small businesses for remote video monitoring, live streaming, mobile-app integration, cloud services, and local device management, making these weaknesses particularly relevant to privacy and IoT security.
CVE-2026-15315 is an authentication bypass vulnerability affecting the camera's local HTTPS management interface on port 443. The researchers found that the authentication process contained an alternate verification path that failed to properly enforce password-based validation. Under certain conditions, an attacker could replay a value generated by the camera and have it accepted as a valid authentication response, allowing the creation of an administrative session without knowing the camera password. The attack does not require a valid account, an existing session, or user interaction, but the attacker must have network access to the vulnerable camera.
Successful exploitation of CVE-2026-15315 could provide administrative-level access to the camera, potentially allowing an attacker to modify device and network settings and access privileged management functions. Depending on the device configuration and available features, this access could potentially expose live video streams or stored recordings, creating significant privacy and surveillance risks. The second vulnerability, CVE-2026-15316, is a denial-of-service flaw in the Wi-Fi onboarding process. The affected firmware insufficiently validated the size of encrypted Wi-Fi credential data before processing it, allowing an unauthenticated attacker on the same network to submit oversized encrypted input that could crash the camera's HTTPS service and prevent legitimate users from accessing or managing the device until the service recovers.
TP-Link was notified of the vulnerabilities by OPSWAT on April 16, 2026, confirmed the findings on July 10, 2026, assigned the CVEs on August 13, 2026, and released fixes on August 18, 2026. Both vulnerabilities were addressed in Tapo C200 firmware V5_1.4.6, or later. Users should immediately update affected cameras to the latest firmware, restrict camera management interfaces to trusted networks, and avoid exposing management services directly to untrusted networks. Organizations should also isolate IoT cameras from critical systems using network segmentation to limit potential lateral movement and reduce the impact of a compromised device.
Impact
- Gain Access
Indicators of Compromise
CVE
CVE-2026-15315
CVE-2026-15316
Remediation
- Update affected TP-Link Tapo C200 cameras to firmware V5_1.4.6 or later immediately.
- Ensure all Tapo cameras are running the latest firmware and regularly check for future security updates.
- Restrict access to the camera’s HTTPS management interface (port 443) to trusted users and networks only.
- Do not expose camera management interfaces directly to the public internet.
- Place IoT cameras on a separate network/VLAN from critical systems to limit potential lateral movement.
- Use strong, unique administrator passwords and change default credentials where applicable.
- Monitor network traffic for unusual authentication attempts or unexpected connections to camera management services.
- If compromise is suspected, isolate the affected camera from the network, update its firmware, and review its configuration and access settings.

