Two newly disclosed vulnerabilities in TP-Link’s Tapo C200 smart camera could allow a nearby network attacker to bypass authentication and gain administrator-level access without knowing the device password This article explores camera provides authentication. . OPSWAT researchers Khoi Tran and Thai Do discovered the flaws, tracked as CVE-2026-15315 and CVE-2026-15316, during the company’s Critical Infrastructure Cybersecurity Graduate Fellowship Program.
TP-Link Tapo Camera Flaw CVE-2026-15315 (Source: opswat) OPSWAT discovered that a fallback verification route failed to adhere to the same credential-validation standards. Under specific circumstances, an intruder can replay the data the camera provides during the authentication process and have the vulnerable logic accept it. This impact may affect privacy-sensitive features like live camera feeds or stored footage, depending on the enabled device features and deployment configuration.
The vulnerable code fails to validate the size of encrypted Wi-Fi credential data before passing it to cryptographic and configuration-related routines. This vulnerability, while not providing administrative access, can disrupt legitimate camera management and affect operational visibility and response times for surveillance deployments. Organizations should place IP cameras and other IoT devices on segmented VLANs, restrict management access to approved hosts, and monitor for unexpected configuration changes or device-service failures.
OPSWAT has identified additional issues in its Tapo C200 research, including a potentially critical flaw, but those findings remain under coordinated disclosure with TP-Link.











.webp?w=1600&fit=1600,900&ssl=1)