Back

TP-Link Tapo C200 Security Camera Vulnerabilities Patched

At a glance

  • Two security flaws found in TP-Link Tapo C200 cameras.
  • Firmware update released on 18 August 2026 to fix issues.
  • Vulnerabilities allowed authentication bypass and denial of service.

Researchers identified security issues in a widely used home and office camera model, leading to a firmware update that addresses the risks.

OPSWAT researchers discovered two vulnerabilities in the TP-Link Tapo C200 security camera, which is frequently used for home monitoring and small office security. These vulnerabilities were assigned identifiers CVE-2026-15315 and CVE-2026-15316. The findings were published by OPSWAT in September 2026.

CVE-2026-15315 allows an attacker with access to the network to bypass authentication by replaying session data, enabling administrative access without a password. This vulnerability could be used to change device settings, manage the camera, and view live or stored video footage. The exploit does not require prior authentication, increasing the risk for affected devices connected to local networks.

The second vulnerability, CVE-2026-15316, involves a denial-of-service condition that can be triggered during Wi-Fi configuration. Insufficient validation of input data may cause the camera’s HTTPS service to crash, disrupting access to the device until it is restarted. Both vulnerabilities affect the same camera model.

What the numbers show

  • Two vulnerabilities identified: CVE-2026-15315 and CVE-2026-15316.
  • Firmware version V5_1.4.6 released on 18 August 2026.
  • Vulnerabilities disclosed by OPSWAT in September 2026.

TP-Link released firmware version V5_1.4.6 on 18 August 2026, which addresses both CVE-2026-15315 and CVE-2026-15316. The update became available before the public disclosure of the vulnerabilities. Users of the Tapo C200 model are advised to install the latest firmware to mitigate potential risks.

The Tapo C200 camera is commonly used for monitoring babies, pets, and as a security device in homes and small offices. Its widespread use increases the importance of timely security updates and vulnerability management. The device’s popularity means that a large number of users could be affected if the vulnerabilities are not addressed.

According to information published by Infosecurity Magazine, an attacker exploiting CVE-2026-15315 could gain control over the camera’s management functions and access sensitive video content. The denial-of-service vulnerability could prevent legitimate users from accessing the camera remotely or locally until service is restored.

Both vulnerabilities were discovered and reported by OPSWAT, which published technical details and coordinated with TP-Link for remediation. The company’s disclosure process included notification of the vendor and release of a public advisory after the patch was made available.

Users are encouraged to verify that their TP-Link Tapo C200 cameras are running firmware version V5_1.4.6 or later to ensure protection against these security issues. Further information on the vulnerabilities and the update process can be found on the OPSWAT and TP-Link websites.

* This article is based on publicly available information at the time of writing.