TP-Link Patched Vulnerabilities in Tapo Security Cameras
Security researchers identified two high-severity flaws that enabled unauthorized network access and device restarts.
Updated on Sept. 23, 2026 in Cybersecurity

Live Poll
Is now a good time to review your smart home device security settings?
Security researchers at OPSWAT identified two critical vulnerabilities affecting TP-Link Tapo C200 and C120 home security cameras. TP-Link has released firmware updates to address the flaws after they were disclosed.
Why it matters
These vulnerabilities highlight the security risks inherent in widespread consumer IoT devices that manage private residential video streams. The findings demonstrate how localized network access can be leveraged to bypass authentication mechanisms.
The login bypass, tracked as CVE-2026-15315, scored 8.7 out of 10, while the crash bug, CVE-2026-15316, received a 7.1 severity rating. These flaws affect the C200 and C120 models, the latter of which sees over 5,000 unit sales per month.
The players
OPSWAT
A cybersecurity firm specializing in critical infrastructure protection and malware analysis.
TP-Link
A global manufacturer of networking hardware and consumer IoT security products.
The details
The login bypass occurs because a secondary verification path in the camera firmware erroneously accepts invalid authentication responses, allowing local network users to access video feeds. The crash bug is triggered by an input validation error where the device processes an oversized chunk of encrypted Wi-Fi credential data. Researchers at OPSWAT have disclosed these issues to the manufacturer, with patches now available for both affected camera models.
Timeline
September 23, 2026: Researchers published the findings regarding the two security vulnerabilities.
The Tech Race
This disclosure follows the pattern of critical security flaws identified in the 2023 Wyze security camera vulnerabilities. It underscores the ongoing struggle to secure low-cost consumer IoT hardware as manufacturers prioritize rapid product iteration over robust authentication testing.
Owners of Tapo C200 and C120 cameras should immediately check the official TP-Link mobile application for mandatory firmware updates. These updates are necessary to close the authentication bypass that currently allows unauthorized users on the same network to view live video and recordings.
The takeaway
The discovery of these vulnerabilities underscores the necessity of keeping IoT devices updated to prevent unauthorized access to private home video feeds. Users should watch for forthcoming security advisories regarding the third, unpatched vulnerability to ensure their devices remain protected.
What happens next
TP-Link is expected to release a firmware patch for the third, currently undisclosed, critical vulnerability found by the researchers.
Further reading
For more context on how IoT firmware security is evolving, visit the Cybersecurity section.
Source note: This article includes information reported by TechRadar.
Live Poll
Is now a good time to review your smart home device security settings?






