Security researchers at OPSWAT have detailed two high-severity flaws in TP-Link’s Tapo C200 and C120 cameras. The C200, a pan-and-tilt indoor camera listed on Amazon for $26.99, is marketed for use as a baby monitor and pet camera.
The more serious flaw can let someone on the same network log in as a camera administrator without the password. That access includes live video, stored recordings and configuration changes. OPSWAT said a compromised C200 used as a baby monitor could expose live video, night vision, crying detection and two-way audio.
The researchers, Khoi Tran and Thai Do of OPSWAT’s Unit 515 team, found that a value returned during the normal challenge-response login could, under certain conditions, be sent back and accepted as a valid authentication response. The result is an administrator session after a small number of requests, without a password or existing session.
The second flaw, CVE-2026-15316, affects only the C200. An oversized encrypted Wi-Fi credential payload can crash its HTTPS service or restart the device. The vulnerabilities are tracked as CVE-2026-15315 and CVE-2026-15316, with scores of 8.7 and 7.1, respectively.
The C200 has recorded over 3,000 Amazon sales, while the current C120 iteration sells over 5,000 units monthly. Its V1 hardware remains compromised until users update the firmware. TP-Link has released firmware updates for both models. OPSWAT also reported one other critical vulnerability but is withholding details while awaiting a patch; no release timeline has been provided.
Comments
0No comments yet. Be the first to comment.