OPSWAT researchers have discovered serious vulnerabilities in TP-Link Tapo C200 security cameras that could allow an attacker on the same network to bypass authentication and gain administrator access without knowing the owner’s password.
The first vulnerability, CVE-2026-15315, carries a CVSS score of 8.7 and can be exploited with only a small number of malicious requests. Once authenticated, an attacker could access privileged camera functions, potentially exposing live video and stored recordings. For cameras used as baby monitors, this could include access to live video, night vision, crying detection and two-way audio.
Researchers also identified CVE-2026-15316, which can be used to crash the camera’s management service and knock the device offline. A third, still-undisclosed vulnerability could allow an attacker to completely compromise the camera and potentially use it as a foothold to target other devices on the same network.
TP-Link released firmware updates addressing the two publicly disclosed vulnerabilities on August 18. OPSWAT is continuing to work with TP-Link on the additional flaw and said further technical details will be released after a fix is available.
Dahvid Schloss, OSCP, Chief Operating Officer, Suzu Labs:
“Camera bugs always get attention because of the “spy factor,” but they usually sound cooler and scarier than they actually are. The main reason not to “worry” about this one is that running this exploit requires local network access, so a threat actor has to be on your Wi-Fi or already own a device that is. If someone’s made it that far into your network, they’re not after the baby monitor. Now, if the camera was port-forwarded to the internet, that’s a bigger design issue and probably should be a concern, but not a common setup for the everyday home user. Either way, I’d still patch the camera, but it’s pretty low on the totem pole of what a cybercriminal wants.
“I’m quite curious about the undisclosed vulnerability that reportedly allows full compromise and a foothold to pivot from. Based on what was reported, I would guess the exploit would be a command injection or a memory-safety bug in the same management service, chained behind that auth bypass to get code execution as root, where they then dropped a static binary to return a shell on the device whose firmware ships with almost no tooling. That attack chain isn’t uncommon on cheap, older consumer IoT devices where security wasn’t top of mind, but if that’s the case here, seeing it hold up on a modern TP-Link device would be a bit of a blast from the past.”
Seemant Sehgal, Founder & CEO, BreachLock:
“A small number of malicious requests to bypass authentication on a device people point at their newborns is the kind of finding that exposes what the word ‘security’ actually means on the label of a home security product.
“These cameras sit on the same network as every other device in the home, so once an attacker has administrator access, the camera stops being just a privacy problem. It becomes a foothold for reaching everything else on that network.
“While firmware patches are available now, the burden falls on device owners to install the update, and most are likely not paying close enough attention to know one exists. This is the part of the disclosure process that consumer devices consistently fail. Enterprise patching has SLAs and dashboards behind it, but a parent with a baby monitor has neither.”
I guess that these cameras need to be unplugged until patches are available. Or the flip side is that since this isn’t the first issue with TP-Link that anyone has encountered, you have to wonder if it is time to ditch the brand entirely.
Related
This entry was posted on September 16, 2026 at 8:07 am and is filed under Commentary with tags TP-Link. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
TP-Link camera flaws could let attackers spy inside homes
OPSWAT researchers have discovered serious vulnerabilities in TP-Link Tapo C200 security cameras that could allow an attacker on the same network to bypass authentication and gain administrator access without knowing the owner’s password.
The first vulnerability, CVE-2026-15315, carries a CVSS score of 8.7 and can be exploited with only a small number of malicious requests. Once authenticated, an attacker could access privileged camera functions, potentially exposing live video and stored recordings. For cameras used as baby monitors, this could include access to live video, night vision, crying detection and two-way audio.
Researchers also identified CVE-2026-15316, which can be used to crash the camera’s management service and knock the device offline. A third, still-undisclosed vulnerability could allow an attacker to completely compromise the camera and potentially use it as a foothold to target other devices on the same network.
TP-Link released firmware updates addressing the two publicly disclosed vulnerabilities on August 18. OPSWAT is continuing to work with TP-Link on the additional flaw and said further technical details will be released after a fix is available.
Dahvid Schloss, OSCP, Chief Operating Officer, Suzu Labs:
“Camera bugs always get attention because of the “spy factor,” but they usually sound cooler and scarier than they actually are. The main reason not to “worry” about this one is that running this exploit requires local network access, so a threat actor has to be on your Wi-Fi or already own a device that is. If someone’s made it that far into your network, they’re not after the baby monitor. Now, if the camera was port-forwarded to the internet, that’s a bigger design issue and probably should be a concern, but not a common setup for the everyday home user. Either way, I’d still patch the camera, but it’s pretty low on the totem pole of what a cybercriminal wants.
“I’m quite curious about the undisclosed vulnerability that reportedly allows full compromise and a foothold to pivot from. Based on what was reported, I would guess the exploit would be a command injection or a memory-safety bug in the same management service, chained behind that auth bypass to get code execution as root, where they then dropped a static binary to return a shell on the device whose firmware ships with almost no tooling. That attack chain isn’t uncommon on cheap, older consumer IoT devices where security wasn’t top of mind, but if that’s the case here, seeing it hold up on a modern TP-Link device would be a bit of a blast from the past.”
Seemant Sehgal, Founder & CEO, BreachLock:
“A small number of malicious requests to bypass authentication on a device people point at their newborns is the kind of finding that exposes what the word ‘security’ actually means on the label of a home security product.
“These cameras sit on the same network as every other device in the home, so once an attacker has administrator access, the camera stops being just a privacy problem. It becomes a foothold for reaching everything else on that network.
“While firmware patches are available now, the burden falls on device owners to install the update, and most are likely not paying close enough attention to know one exists. This is the part of the disclosure process that consumer devices consistently fail. Enterprise patching has SLAs and dashboards behind it, but a parent with a baby monitor has neither.”
I guess that these cameras need to be unplugged until patches are available. Or the flip side is that since this isn’t the first issue with TP-Link that anyone has encountered, you have to wonder if it is time to ditch the brand entirely.
Share this:
Like this:
Related
This entry was posted on September 16, 2026 at 8:07 am and is filed under Commentary with tags TP-Link. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.