TP-Link Patches Local Authentication Bypass Flaws in Tapo Home Security Cameras
Vulnerabilities in popular Tapo models let local network users access live video and administrative settings without a password before applying firmware updates.

Security researchers at cybersecurity firm OPSWAT have detailed two high-severity security vulnerabilities affecting TP-Link's Tapo C200 and Tapo C120 home security cameras, as reported by TechRadar Pro (https://www.techradar.com/pro/security/these-popular-tp-link-home-security-cameras-could-be-hacked-to-spy-on-you-while-you-sleep-experts-warn). The more serious flaw allows an attacker on the same local network to gain administrative control of the device without providing a password.
The affected models represent widely purchased consumer IoT hardware. The pan-and-tilt Tapo C200, which retails on Amazon for $26.99 and is commonly marketed as a baby monitor and pet camera, has recorded more than 3,000 sales on Amazon. The Tapo C120 logs over 5,000 monthly unit sales, with its V1 hardware version vulnerable until updated.
The primary flaw, tracked as CVE-2026-15315 with a CVSS severity score of 8.7, resides in the local HTTPS management interface used by both cameras. The devices employ a challenge-response authentication mechanism designed to verify the owner's password. OPSWAT graduate fellow Khoi Tran and Unit 515 mentor Thai Do discovered an alternate verification path where a session value generated by the camera during login can be returned to the device and accepted as valid authentication after a small number of requests.
Exploiting CVE-2026-15315 establishes an administrator session without requiring an existing login or password. On a C200 device configured as a nursery monitor, this grants access to live video feeds, stored recordings, night vision settings, crying detection features, two-way audio streams, and device configuration settings.
The second flaw, CVE-2026-15316, carries a severity score of 7.1 and affects only the Tapo C200. Located in the camera's Wi-Fi onboarding code, the bug allows a local actor to transmit an oversized package of encrypted Wi-Fi credential data, crashing the device's HTTPS service or forcing a hardware reboot that cuts off monitoring until recovery.
Exploitation of both vulnerabilities requires adjacent network access, meaning an attacker must already be connected to the local Wi-Fi network or trusted environment. TP-Link has issued firmware updates for both models to address CVE-2026-15315 and CVE-2026-15316.
OPSWAT also identified a third, critical vulnerability that could allow an attacker to achieve full camera compromise and establish a persistent network foothold. Details on that vulnerability remain withheld pending an upcoming patch from TP-Link, for which neither organization has published a release timeline.
Sources
Written by
The Company Wire
Inside the companies building what’s next. Reporting on startups, technology, funding and the people shaping them.



