Skip to content

Security1 publisher2 min readPublished

Replaying camera traffic on the LAN gets admin on TP-Link's Tapo C200

An attacker already on the camera's network can replay traffic into an administrative session on an unpatched Tapo C200 and reach its live video. TP-Link's fix shipped in August.

The Watch · Security desk

Photograph accompanying Replaying camera traffic on the LAN gets admin on TP-Link's Tapo C200
Photo: bankinfosecurity.asia

What happened

  • OPSWAT published details of two vulnerabilities in the TP-Link Tapo C200, a camera sold for baby and pet monitoring, home security and small-office surveillance.
  • CVE-2026-15315 is a replay-based authentication bypass that gives an attacker with network access to the camera a valid administrative session without knowing or recovering the owner's password.
  • TP-Link patched both bugs in firmware version V5_1.4.6, which the manufacturer released on August 18.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure Any C200 left on pre-V5_1.4.6 firmware is a working admin console for whoever reaches its subnet, including a contractor's laptop on a branch LAN or a guest network that was never segmented.
  • contradiction OPSWAT presents the bypass as a route to live streams and stored recordings; Schloss argues the same-network requirement means whoever is already inside has better targets. The two readings imply different patch urgency for the same CVE.
  • decision Fleet owners choose between touching every camera now and waiting for the critical bug's advisory, by which point a fix will exist and so will the technical detail attackers want.

CVE-2026-15315 needs an attacker on the camera's own network, and that precondition is where the two published bugs get argued about. Dahvid Schloss, COO at Suzu Labs, said the flaw is less dangerous than it sounds because an attacker would have to be on the same network as the camera [7]. "If someone's made it that far into your network, they're not after the baby monitor," he said [8]. He named one exception: "Now, if the camera was port-forwarded to the internet, that's a bigger design issue and probably should be a concern, but not a common setup for the everyday home user." [9]

OPSWAT's account of the same bug is about what the session opens. The administrative access "enables the attacker to invoke privileged management functions, modify device configuration and perform operations that would normally require authorized administrator access," OPSWAT wrote [5]. The same advisory said that access "may also expose privacy-sensitive camera functionality, including live video streams and stored recordings, enabling unauthorized surveillance of footage captured by the affected device" [6].

The second bug is thinner. CVE-2026-15316 sits in the onboarding configuration flow, where encrypted credential data needs to be validated before it is passed to cryptographic and configuration-processing routines [10]. "An unauthenticated attacker with network access to the camera can submit an oversized encrypted credential value," OPSWAT wrote [11], and when that malformed data reaches the vulnerable processing path it can crash the camera's HTTPS service [12]. Both published bugs are rated high severity [13].

The one still open is the one OPSWAT rates critical. It "could allow an attacker to fully compromise the camera and use the compromised device as a foothold within the network," the company said [15], and it is working with TP-Link on that bug now [14]. Schloss guessed at how it works: "a command injection or a memory-safety bug in the same management service, chained behind that auth bypass to get code execution as root" [16]. That is a guess from outside the research, not OPSWAT's description. OPSWAT said details will be shared once a fix is available [17].

Three flaws in one camera's management surface, then: two closed in V5_1.4.6 on August 18, one open [18]. The reporting on the disclosure does not mention exploitation in the wild [19]. Anyone running C200s across branch sites has the interval between now and that third advisory to get the August firmware onto the fleet.

What to watch

  • A CVE number and firmware release for the third flaw, and whether it chains behind CVE-2026-15315.
  • Any report of exploitation against internet-exposed, port-forwarded Tapo C200 units.
  • Whether TP-Link pushes V5_1.4.6 automatically or leaves owners to pull it by hand.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories