Skip to main content
LiMP VPN
All news

TP-Link Tapo C200: Zero-Days Let Attackers Watch Your Home Camera

TP-Link Tapo C200: Zero-Days Let Attackers Watch Your Home Camera

In short: On September 16, 2026, OPSWAT researchers disclosed two zero-day vulnerabilities in the popular TP-Link Tapo C200 home security camera — CVE-2026-15315 and CVE-2026-15316. The first allows an attacker on the same local network to gain full administrative access without knowing the password and watch the live video stream. Firmware update V5_1.4.6, released August 18, patches both flaws. A third, critical-severity zero-day remains unpatched.

What Happened: Zero-Days in the Best-Selling Home Camera

The TP-Link Tapo C200 is one of the world's best-selling home IP cameras, widely used for baby monitoring, pet surveillance, and home security. On September 16, 2026, OPSWAT published details of two vulnerabilities in the camera's firmware — both exploitable from the local network: a home Wi-Fi, a small office network, or any shared wireless connection the camera is on. For more on why home network security matters, visit our privacy blog.

The vulnerabilities were found during a routine security audit of smart home devices. OPSWAT notified TP-Link in advance and coordinated patch release before publishing the first two CVEs — a responsible disclosure practice that gives manufacturers time to fix flaws before they are weaponised at scale. However, even with a patch available, most users do not update IoT device firmware promptly — or at all.

CVE-2026-15315: Admin Access Without a Password

The more dangerous of the two, CVE-2026-15315 is an authentication bypass via replay attack. The camera uses session tokens that are not properly invalidated after a session ends. An attacker with access to the network can intercept or replay a previously used token to obtain a valid administrative session — no password required, no interaction from the owner needed.

Once exploited, the attacker gains full administrative control over the device:

  • watching the live video feed in real time;
  • accessing stored recordings on the memory card or in cloud storage;
  • modifying device settings — disabling motion alerts, changing passwords, redirecting traffic;
  • using the compromised camera as a pivot point to attack other devices on the home network.

A camera installed to protect your home becomes a surveillance tool turned against you — with no visible sign of intrusion. The status light blinks normally, the app shows nothing unusual, yet someone has already been watching your home.

CVE-2026-15316: Network-Based Denial of Service

CVE-2026-15316 allows an unauthenticated attacker on the same network to submit malformed encrypted data during the camera's onboarding configuration flow. The device cannot validate the data, its HTTPS service crashes, and the camera goes offline until it fully restarts.

A denial-of-service may sound less alarming than an auth bypass, but in a home security context it is particularly dangerous: an attacker can silently disable your camera at will — just before breaking into your home, for example. You assume the camera is recording; it has been down for minutes. This combination of DoS plus physical opportunity makes CVE-2026-15316 a serious real-world threat, not just a lab curiosity.

Third Vulnerability: Critical, Still Unpatched

The most concerning part of OPSWAT's report is the mention of a third, critical-severity vulnerability in the same Tapo C200 camera. Researchers are conducting coordinated disclosure with TP-Link, so technical details are being withheld until a patch is available. According to OPSWAT, it may allow an attacker to fully compromise the camera and establish a persistent foothold in the home network — with the ability to then target other connected devices. No timeline for the fix has been announced.

This means that even after applying the current firmware update, your camera contains an unknown critical attack surface. The safest interim step is to isolate the camera on a separate network segment — a guest Wi-Fi — so that even if the device is compromised, the attacker cannot pivot to your laptops, smartphones, or NAS drives. Learn how LiMP VPN features can add an encryption layer to connected home devices.

How to Protect Yourself Right Now

  1. Update to firmware V5_1.4.6 or newer immediately. Open the Tapo app → select your camera → Settings (gear icon) → Device Info → Firmware Version. Install any available update without delay.
  2. Change your Tapo account password. Even after updating: if a session token was previously captured by an attacker, a password change forces all active sessions to be invalidated and regenerated.
  3. Isolate IoT devices on a separate Wi-Fi segment. Most modern home routers support a guest network — move the camera there. Devices on the guest segment cannot see the main network, so even a compromised camera cannot reach your computers, phones, or smart speakers.
  4. Disable remote access to the camera if you do not actively use it. Every open port is an additional attack surface exposed to the internet.
  5. Monitor TP-Link's official channels for the critical patch for the third vulnerability — install it as soon as it is released via the Tapo app or the TP-Link support site.

For broader home network protection, a router-level VPN encrypts all outbound traffic, making external network reconnaissance significantly harder for attackers. See the LiMP VPN plans — one subscription covers all devices in your home.

Sources

TP-Link Tapo C200: Zero-Days Let Attackers Watch Your Home Camera