TP-Link patched two vulnerabilities in its Tapo C200 smart cameras that allow attackers on the same network to hijack an administrative session or disrupt the camera's HTTPS service. CVE-2026-15315 allows replay of camera-generated authentication material in the local HTTPS management interface, potentially exposing live video, stored recordings, and administrative functions without the camera password. CVE-2026-15316 allows an unauthenticated attacker to send an oversized encrypted Wi-Fi credential during onboarding and crash the HTTPS service.
OPSWAT reported the issues to TP-Link on April 16; TP-Link confirmed them on July 10, assigned CVEs on August 13, and released the remediation in Tapo C200 firmware V5_1.4.6 on August 18. OPSWAT also disclosed that it reported a separate critical, currently undisclosed flaw that could fully compromise a camera and establish a foothold on the local network; technical details remain withheld pending a fix.

See affected versions and whether adversaries are exploiting it.
5 events from the most recent confirmed update back to the earliest known activity.
TP-Link released Tapo C200 firmware V5_1.4.6, fixing CVE-2026-15315 and CVE-2026-15316. The flaws could respectively enable a network attacker to obtain an administrative session or crash the camera's HTTPS service.
TP-Link assigned CVE-2026-15315 to the local HTTPS authentication-bypass issue and CVE-2026-15316 to the oversized encrypted-credential denial-of-service issue.
TP-Link confirmed OPSWAT's findings for the two Tapo C200 vulnerabilities, including the replay-based administrative-session bypass and HTTPS-service denial of service.
OPSWAT researchers reported the authentication-bypass flaw CVE-2026-15315 and Wi-Fi onboarding denial-of-service flaw CVE-2026-15316 affecting TP-Link Tapo C200 cameras to TP-Link.
OPSWAT reported a separate undisclosed critical zero-day in TP-Link cameras that could reportedly permit full camera compromise and provide a foothold on the local network. OPSWAT and TP-Link are working on a fix, with technical details withheld pending remediation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
cryptika.com
Open sourcecybersecuritynews.com
Open sourceinfosecurity-magazine.com
Open sourceopswat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.