High severity8.8NVD Advisory· Published Aug 18, 2026· Updated Sep 4, 2026
CVE-2026-15315
CVE-2026-15315
Description
Tapo C120 v1 and C200 v5 contain an improper authentication vulnerability within the login authentication verification module. An attacker on the local network can exploit weaknesses in challenge parameter validation to bypass normal authentication controls and obtain administrative session tokens.
Successful exploitation may allow an attacker to subsequently execute privileged management actions, enable unauthorized administrative access and temporary disruption of device services, resulting in a denial-of-service (DoS) condition.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2Patches
Vulnerability mechanics
References
5- www.tp-link.com/us/support/faq/5248/nvdVendor AdvisoryPatch
- www.tp-link.com/en/support/download/tapo-c120/v1.26/nvdRelease NotesProduct
- www.tp-link.com/en/support/download/tapo-c200/v5/nvdProductRelease Notes
- www.tp-link.com/us/support/download/tapo-c120/v1.26/nvdRelease NotesProduct
- www.tp-link.com/us/support/download/tapo-c200/v5/nvdProductRelease Notes
News mentions
5- ⚡ Weekly Recap: Cisco 0-Day, AI Agent RCE, ClickFix Attacks, ClickFix Surge, and Browser HijacksThe Hacker News · Sep 21, 2026
- In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP FlawSecurityWeek · Sep 18, 2026
- TP-Link Cameras 0-Day Vulnerabilities Allow Attackers to Spy on UsersCyber Security News · Sep 16, 2026
- Zero-Day Flaw in TP-Link Cameras Enables EavesdroppingInfosecurity Magazine · Sep 16, 2026
- TP-Link: Eight Vulnerabilities Disclosed, High-Severity Flaws Hit TL-MR6400 v7 RouterVypr Intelligence · Aug 21, 2026