Zero-Day Flaws in TP-Link Cameras Allow Eavesdropping and DoS
Two zero-day vulnerabilities discovered in TP-Link Tapo C200 cameras by OPSWAT researchers enable unauthorized access to camera feeds and denial-of-service conditions.

OPSWAT researchers have disclosed two critical zero-day vulnerabilities affecting TP-Link Tapo C200 cameras, commonly deployed for home, baby monitoring, and small office security. The flaws, identified as CVE-2026-15315 and CVE-2026-15316, were patched by TP-Link in firmware version V5_1.4.6, released on August 18.
CVE-2026-15315 is an authentication bypass vulnerability that leverages replay attacks. An attacker with network access to the camera can exploit this flaw to establish a valid administrative session without needing to know or recover the user's password. This level of access allows an attacker to invoke privileged management functions, modify device configurations, and access sensitive camera data.
"This access may also expose privacy-sensitive camera functionality, including live video streams and stored recordings, enabling unauthorized surveillance of footage captured by the affected device," OPSWAT stated. While the vulnerability requires network access to the camera, its potential for eavesdropping on private spaces is a significant concern.
CVE-2026-15316 is a denial-of-service (DoS) vulnerability that impacts the camera's onboarding configuration process. The flaw lies in the validation of encrypted credential data before it is passed to cryptographic and configuration-processing routines. An unauthenticated attacker on the same network can submit an oversized encrypted credential value, causing the camera's HTTPS service to crash and rendering the device inoperable.
Adding to these concerns, OPSWAT is collaborating with TP-Link on a third, critical zero-day vulnerability. This undisclosed flaw could potentially allow an attacker to fully compromise the camera and use it as an entry point into the target network. Security experts speculate this could involve command injection or memory-safety bugs, chained with the authentication bypass to achieve root-level code execution.
While the immediate impact of CVE-2026-15315 and CVE-2026-15316 is mitigated by the firmware update, the existence of a third, more severe vulnerability highlights ongoing security challenges in the IoT device market. The potential for full device compromise and network infiltration underscores the need for diligent patching and network segmentation, especially for devices handling sensitive data.
Users of TP-Link Tapo C200 cameras are strongly advised to update their firmware to version V5_1.4.6 or later to protect against these vulnerabilities. Further details on the critical third vulnerability will be released once a fix is available, emphasizing the continuous cat-and-mouse game between security researchers and device manufacturers in securing the expanding IoT ecosystem.