Improper Authentication Vulnerability in Tapo C200 Version 5 by TP-Link
CVE-2026-15315

8.7HIGH

Key Information:

Vendor
CVE Published:
18 August 2026

Badges

๐Ÿ“ˆ Score: 1,140๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC๐Ÿ“ฐ News Worthy

What is CVE-2026-15315?

CVE-2026-15315 is a significant vulnerability found in the Tapo C120 version 1 and Tapo C200 version 5 IP cameras, manufactured by TP-Link Systems Inc. These devices are designed for home security and surveillance, offering users the ability to monitor their premises remotely. The vulnerability arises from improper authentication mechanisms within the login verification module. Specifically, it allows an attacker on the local network to exploit flaws in the validation of challenge parameters and bypass standard authentication controls. Successful exploitation could result in unauthorized access to administrative session tokens, enabling the attacker to execute privileged actions that could compromise the integrity and security of the device. This could lead to unauthorized administrative access and potential disruptions in device services, resulting in operational challenges for organizations relying on these devices for security.

Potential Impact of CVE-2026-15315

  1. Unauthorized Administrative Access: The vulnerability allows attackers to gain privileged access to the device, enabling them to alter configurations, monitor streams, or manipulate settings without the ownerโ€™s consent.

  2. Service Disruption: Exploitation may lead to a temporary denial-of-service (DoS) condition, which can interrupt the security monitoring capabilities of the camera, leaving the premises vulnerable and unprotected during the downtime.

  3. Compromise of Security and Privacy: With administrative access, attackers could potentially access sensitive video footage and personal data, leading to privacy violations and further exploitation of the compromised system, impacting the overarching security posture of an organization.

Affected Version(s)

Tapo C120 v1 0 < 1.9.3 Build 260521

Tapo C200 v5 0

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

News Articles

TP-Link camera flaws expose feeds to unauthorised access

Two security flaws in TP-Link Tapo cameras can let attackers bypass authentication gain administrator access and potentially view live video or stored

2 weeks ago

TP-Link Cameras 0-Day Vulnerabilities Allow Attackers to Spy on Users

Two zero-day flaws in TP-Link Tapo C200 cameras could let same-network attackers bypass authentication or disrupt camera services.

2 weeks ago

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • ๐Ÿ“ฐ

    First article discovered by Cybersecuritynews

  • Vulnerability published

  • Vulnerability Reserved

Credit

Thai Do (Lio) and Khoi Tran (KayTii) from OPSWAT
.