
Security researchers at the US cybersecurity vendor OPSWAT have discovered a vulnerability in TP-Link’s Tapo C200 indoor surveillance camera. In fact, there are two vulnerabilities, with a high severity rating. One of these allows threat actors to spy on homes and businesses. Fortunately, TP-Link patched these in August.
TP-Link Tapo C200 camera vulnerability could give hackers access to live footage
Security researchers have found multiple vulnerabilities in TP-Link’s Tapo C200 indoor security camera, including a critical flaw that has yet to be fully patched. OPSWAT says the critical issue could let an attacker take full control of the camera and use it to gain access to other devices on the same network. The researchers have not revealed whether the attack requires local network access.
The firm says it continues to work closely with TP-Link on the “validation and remediation” of the flaw. It’ll share further technical details once appropriate fixes are available, and the “coordinated disclosure process” is complete.
Admin sessions without a password
Besides this, the researchers examined the product’s firmware and local communication processes and discovered two other vulnerabilities. There’s an authentication bypass flaw and a denial-of-service vulnerability. The former is CVE-2026-15315, with a severity score of 8.7/10. The latter is tracked as CVE-2026-15316 and has a severity score of 7.1/10.
OPSWAT says the former lets attackers obtain valid admin sessions without a password. This could give them control of the device and access to the live stream. Meanwhile, the latter allows threat actors to send “oversized crypted ciphertext values” that can trigger exception-handling failures due to insufficient validation, causing the affected device to crash or restart.
Successful exploitation can result in a temporary disruption of HTTPS management and monitoring. This results in a denial-of-service (DoS) until the service is restored.
Patched the vulnerabilities in August
OPSWAT reported the flaws to TP-Link in April 2026, and the company started working on a fix in July. TP-Link released firmware version V5_1.4.6 on August 18, 2026. This apparently fixes both issues. So if you own the C200 security camera, it’s a good idea to install the update through the Tapo app as soon as possible. The researchers did not say whether attackers are actively exploiting these flaws or how widespread any abuse may be.
The post TP-Link Tapo C200 Has Critical Flaws That Could Let Hackers Spy on You appeared first on Android Headlines.