Authentication Bypass Vulnerability in Tapo Cameras by TP-Link
CVE-2026-78578
7.1HIGH
Key Information:
- Vendor
Tp-link Systems Inc.
- Status
- Vendor
- CVE Published:
- 1 October 2026
What is CVE-2026-78578?
The TP-Link Tapo C120 and C200 cameras are vulnerable due to a failure to enforce authentication for specific HTTPS onboarding actions after initial setup. This vulnerability allows an unauthenticated adjacent attacker to exploit the do method to submit unauthorized wireless configuration parameters, facilitating the connection of the camera to a different network. Such exploitation results in the camera losing access to its intended wireless network, rendering it unreachable on its management interface and leading to a denial-of-service condition.
Affected Version(s)
Tapo C120 v1 0
Tapo C200 v5 0
References
CVSS V4
Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Thai Do (Lio) and Khoi Tran (KayTii) from OPSWAT
