Authentication Bypass Vulnerability in Tapo Cameras by TP-Link
CVE-2026-78578

7.1HIGH

What is CVE-2026-78578?

The TP-Link Tapo C120 and C200 cameras are vulnerable due to a failure to enforce authentication for specific HTTPS onboarding actions after initial setup. This vulnerability allows an unauthenticated adjacent attacker to exploit the do method to submit unauthorized wireless configuration parameters, facilitating the connection of the camera to a different network. Such exploitation results in the camera losing access to its intended wireless network, rendering it unreachable on its management interface and leading to a denial-of-service condition.

Affected Version(s)

Tapo C120 v1 0

Tapo C200 v5 0

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Thai Do (Lio) and Khoi Tran (KayTii) from OPSWAT
.