< Back to all clusters
[TECHNOLOGY] · United States · 7 sources

started · updated

TP-Link Tapo C200 cameras found to have security vulnerabilities

Security researchers at OPSWAT have identified several vulnerabilities in TP-Link’s Tapo C200 indoor surveillance cameras. These flaws could allow an attacker with access to the user's local network to bypass authentication and gain administrator privileges without a password.

Specifically, the vulnerability designated CVE-2026-15315 allows unauthorized access to privileged functions, potentially exposing live video, night vision, and two-way audio. Another flaw, CVE-2026-15316, can be used to crash the device's management service, knocking the camera offline.

Researchers also noted a third, undisclosed vulnerability that could allow an attacker to use the camera as a foothold to target other devices on the same network. TP-Link released firmware updates on August 18 to address the two publicly disclosed vulnerabilities and is working with OPSWAT to remediate the remaining flaw.

Entities

OPSWAT · TP-Link · Tapo C200