Arbitrary Command Execution Vulnerability in Tapo Indoor Cameras by TP-Link
CVE-2026-102369

8.7HIGH

What is CVE-2026-102369?

The Tapo C120 and C200 cameras exhibit a vulnerability due to insufficient protection of login challenge data and lack of input sanitization in the MacTool handler. This makes it possible for an unauthorized attacker on the same local network to replay such data, circumventing standard authentication mechanisms to gain administrative access. The attacker can subsequently enable a privileged service, making it accessible even after a system reboot. By executing crafted input, they can carry out arbitrary commands within the device management process. Successful exploitation can lead to a significant compromise of the camera's functionality and security, affecting its confidentiality, integrity, and availability.

Affected Version(s)

Tapo C120 v1 0

Tapo C200 v5 0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Thai Do (Lio) and Khoi Tran (KayTii) from OPSWAT
.