Arbitrary Command Execution Vulnerability in Tapo Indoor Cameras by TP-Link
CVE-2026-102369
Key Information:
- Vendor
Tp-link Systems Inc.
- Status
- Vendor
- CVE Published:
- 1 October 2026
What is CVE-2026-102369?
The Tapo C120 and C200 cameras exhibit a vulnerability due to insufficient protection of login challenge data and lack of input sanitization in the MacTool handler. This makes it possible for an unauthorized attacker on the same local network to replay such data, circumventing standard authentication mechanisms to gain administrative access. The attacker can subsequently enable a privileged service, making it accessible even after a system reboot. By executing crafted input, they can carry out arbitrary commands within the device management process. Successful exploitation can lead to a significant compromise of the camera's functionality and security, affecting its confidentiality, integrity, and availability.
Affected Version(s)
Tapo C120 v1 0
Tapo C200 v5 0
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
