Improper Input Validation Vulnerability in Tapo C200 by TP-Link
CVE-2026-15316

7.1HIGH

Key Information:

Vendor
CVE Published:
18 August 2026

Badges

๐Ÿ‘พ Exploit Exists๐Ÿ“ฐ News Worthy

What is CVE-2026-15316?

An improper input validation vulnerability exists in the configuration service of TP-Link's Tapo C200 v5, affecting its ability to process encrypted credential data. By sending oversized encrypted ciphertext values, an attacker may trigger exception handling failures due to inadequate validation, which can lead to device crashes or restarts. This exploitation could result in temporary disruptions of HTTPS management and monitoring functionalities, essentially causing a denial-of-service condition until the service is restored.

Affected Version(s)

Tapo C200 v5 0

News Articles

TP-Link camera flaws expose feeds to unauthorised access

Two security flaws in TP-Link Tapo cameras can let attackers bypass authentication gain administrator access and potentially view live video or stored

2 weeks ago

TP-Link Cameras 0-Day Vulnerabilities Allow Attackers to Spy on Users

Two zero-day flaws in TP-Link Tapo C200 cameras could let same-network attackers bypass authentication or disrupt camera services.

2 weeks ago

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • ๐Ÿ‘พ

    Exploit known to exist

  • ๐Ÿ“ฐ

    First article discovered by Cybersecuritynews

  • Vulnerability published

  • Vulnerability Reserved

Credit

Thai Do (Lio) and Khoi Tran (KayTii) from OPSWAT
.