TP-Link Cameras 0-Day Vulnerabilities Allow Attackers to Spy on Users

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

TP-Link Tapo C200 smart cameras were affected by two zero-day vulnerabilities that could allow attackers on the same network to bypass authentication or disrupt camera services.

The flaws, tracked as CVE-2026-15315 and CVE-2026-15316, were fixed in firmware version V5_1.4.6, released on August 18, 2026.

TP-Link Tapo cameras are widely deployed in homes and small businesses for remote video monitoring. The devices provide live video streaming, mobile-app integration, cloud-connected features, and local management services. However, their network connectivity can also create an entry point for attackers if security controls fail.

The vulnerabilities were discovered by OPSWAT researchers Khoi Tran and Thai Do as part of the company’s Critical Infrastructure Cybersecurity Graduate Fellowship Program. The researchers examined the Tapo C200 firmware and local communication functions in a controlled laboratory environment.

CVE-2026-15315 is an authentication bypass vulnerability in the camera’s local HTTPS management interface. The Tapo C200 exposes its management service over HTTPS on port 443 and uses a challenge-response process to verify users before creating an authenticated session.

In a secure challenge-response system, the device sends a challenge to the user, and the client must return a correct response derived from the administrator’s password. OPSWAT found that the affected camera included an alternate verification path that did not properly enforce password-based validation.

CVE-2026-1531 (Source: OPSWAT)
CVE-2026-1531 (Source: OPSWAT)

Under certain conditions, an attacker could replay a value the camera generated during authentication. The device could then accept that value as valid and create an administrative session without requiring the attacker to know the camera password.

This means a threat actor with network access to a vulnerable Tapo C200 could potentially gain administrator-level access through only a small number of requests. No valid account, existing session, or user interaction is required.

Administrative access could allow an attacker to change device settings, alter network configuration, access privileged management functions, and potentially view privacy-sensitive camera features. This could expose live camera feeds or stored recordings, creating a serious surveillance and privacy risk for affected users.

The second flaw, CVE-2026-15316, is a denial-of-service vulnerability in the camera’s Wi-Fi onboarding process. During onboarding, the device processes encrypted Wi-Fi credential data.

OPSWAT found that the affected firmware did not properly validate the size of encrypted data before sending it to cryptographic and configuration-processing functions.

CVE-2026-15316 (Source: OPSWAT)
CVE-2026-15316 (Source: OPSWAT)

An unauthenticated attacker on the network could send an oversized encrypted credential value to the vulnerable service. The malformed input could crash the camera’s HTTPS service, preventing legitimate users from accessing or managing the device until the service recovers.

The issue does not require authentication or direct interaction with the victim. However, the attacker must have network access to the camera, such as a local Wi-Fi network, a compromised internal system, or an improperly exposed management interface.

OPSWAT reported the vulnerabilities to TP-Link on April 16, 2026. TP-Link confirmed the findings on July 10 and released patches on August 18. The company assigned CVE-2026-15315 and CVE-2026-15316 on August 13.

Users should update affected TP-Link Tapo C200 cameras to firmware version V5_1.4.6 or later immediately. Restrict camera management interfaces to trusted networks, and businesses should place IoT devices on separate network segments to reduce the impact of a compromise.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

The post TP-Link Cameras 0-Day Vulnerabilities Allow Attackers to Spy on Users appeared first on Cyber Security News.