CVE-2026-15316(tp-link / tapo_c200)

LOWCVSS 6.5 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

An improper input validation vulnerability in the configuration service for processing encrypted credential data has been identified in Tapo C200 v5.  An attacker can send oversized crypted ciphertext values that may trigger exception handling failures, due to insufficient validation, causing the affected device to crash or restart. Successful exploitation may temporarily disrupt HTTPS management and monitoring functionality, resulting in a denial-of-service (DoS) condition until the service recovers.

0.0/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-20

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • tapo_c200
  • tapo_c200_firmware

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Peaked at 2 mentions on most recent observed day (2026-09-17)
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
tapo_c200tapo_c200_firmware

1 version affected across 2 products

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-09-16: 1Mentions · 2026-09-17: 209-1609-17
Referenced assets2 URLs
Full discourse3 posts
  • elhacker.NET@elhackernet

    Vulnerabilidades 0-day en cámaras TP-Link permiten espiar usuarios Se han detectado dos vulnerabilidades de día cero (CVE-2026-15315 y CVE-2026-15316) en las cámaras inteligentes TP-Link Tapo C200 https://blog.elhacker.net/2026/09/vulnerabilidades-0-day-en-camaras-tp.html

    060911.1K
    141.9K followersView on X
  • Rıdvan Yağlı@ridvanyagli

    🔴 TP-Link Tapo C200 model güvenlik kamerası ürününde iki güvenlik açığı tespit edildi! CVE-2026-15315: Aynı ağdaki kimlik doğrulanmamış saldırgan, authentication mekanizmasını aşarak yönetici oturumu elde edebiliyor. Bu durum kamera görüntülerine ve yönetim işlevlerine erişim riski oluşturuyor. Erişim sonrası saldırgan sizi izleyebiliyor. CVE-2026-15316: Kimlik doğrulama gerektirmeyen saldırgan, özel hazırlanmış veriler göndererek kameranın HTTPS servisini çökertebiliyor (DoS). Tapo C200 V5 için açıklar V5_1.4.6 Build 260709 sürümünde düzeltildi. Kameranızı güncelleyin.

    22071776
    2.3K followersView on X
  • The Daily Tech Feed@dailytechonx

    Urgent for anyone running TP-Link Tapo C200 cameras: two zero-day vulnerabilities—an auth bypass (CVE-2026-15315) and DoS flaw (CVE-2026-15316)—were patched in firmware V5_1.4.6 on August 18, 2026. Attackers sharing your network could access your camera’s admin functions or crash its service. Tighten your Wi-Fi security and isolate IoT devices until you’ve updated—all things that matter for privacy & security. #Security #IoT #TPLink #Vulnerability #TechNews #Cybersecurity https://thedailytechfeed.com/tp-link-tapo-c200-cameras-had-critical-0-day-flaws-allowing-remote-control/

    0000057
    722 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWtp-linktapo_c2005.0--
OStp-linktapo_c200_firmware---

Explore more