Security researchers have released details of two zero-day vulnerabilities found in TP-Link security cameras commonly used in and small offices, one of which could enable attackers to spy on users.
OPSWAT said the bugs affect the TP-Link Tapo C200 camera often used for baby/pet monitoring, security and SOHO business security.
CVE-2026-15315 and CVE-2026-15316 were patched by the Chinese manufacturer in firmware version V5_1.4.6 released on August 18.
CVE-2026-15315 is an authentication bypass through replay which could allow an attacker with network access to the camera to obtain a valid administrative session without knowing or recovering the user's password.
“The resulting administrative access enables the attacker to invoke privileged management functions, modify device configuration and perform operations that would normally require authorized administrator access,” OPSWAT explained.
“This access may also expose privacy-sensitive camera functionality, including live video streams and stored recordings, enabling unauthorized surveillance of footage captured by the affected device.”
Dahvid Schloss, COO at Suzu Labs, said the high-severity flaw is less dangerous than it sounds, because an attacker would have to be on the same network as the camera in order for it to work.
“If someone's made it that far into your network, they're not after the baby monitor,” he added. “Now, if the camera was port-forwarded to the internet, that's a bigger design issue and probably should be a concern, but not a common setup for the everyday user.”
CVE-2026-15316 is a denial-of-service vulnerability which impacts the camera's onboarding configuration flow. Encrypted credential data needs to be validated before being passed to cryptographic and configuration-processing routines.
“An unauthenticated attacker with network access to the camera can submit an oversized encrypted credential value,” OPSWAT wrote. “When the malformed data reaches the vulnerable processing path, it can cause the camera's HTTPS service to crash, resulting in a denial-of-service condition.”
A Third Vulnerability Could Be Worse
While both of the published vulnerabilities are high severity, OPSWAT is currently working with the camera-maker on an additional zero day it found, which it rates as critical.
“It could allow an attacker to fully compromise the camera and use the compromised device as a foothold within the network,” OPSWAT claimed.
“I would guess the exploit would be a command injection or a memory-safety bug in the same management service, chained behind that auth bypass to get code execution as root, where they then dropped a static binary to return a shell on the device whose firmware ships with almost no tooling,” said Suzu Labs’ Schloss.
“That attack chain isn't uncommon on cheap, older consumer IoT devices where security wasn't top of mind, but if that's the case here, seeing it hold up on a modern TP-Link device would be a bit of a blast from the past.”
Details will be shared once a fix is available.
Image credit: tinhkhuong / Shutterstock.com
US Government Ordered to Urgently Patch Apple Zero-Day Bugs News 12 September 2023
US Government Ordered to Urgently Patch Apple Zero-Day Bugs
#BSidesBelfast: Focus More on Common Attacks, Less on Zero-Days News 31 October 2019
#BSidesBelfast: Focus More on Common Attacks, Less on Zero-Days
Microsoft Fixes 400 Flaws on August Patch Tuesday News 12 August 2026
Microsoft Fixes 400 Flaws on August Patch Tuesday
Microsoft Fixes 200 CVEs in June Patch Tuesday News 10 June 2026
Microsoft Fixes 200 CVEs in June Patch Tuesday
Microsoft Reports Severe Zero-Day Flaw in On-Prem Exchange Servers News 15 May 2026
Microsoft Reports Severe Zero-Day Flaw in On-Prem Exchange Servers
What’s Hot on Infosecurity Magazine?
Microsoft Releases Emergency Patch to Fix RDS Vulnerability
Revolut Confirms Data Breach Through Fake Government Requests
Hackers Exploit Maximum Severity Flaw in GitLab
OpenAI Agent Swarm Hacks RubyGems Package Manager
Human Attacker Hits Machine-Speed Exploitation of Marimo RCE
Malicious Twitch Extension Exposes 31,000 Users' OAuth Tokens
Anthropic Reveals Yet Another Cybersecurity Incident
FBI Publishes First-Ever Cyber Strategy, With Focus on Disrupting Threat Actors
Defense Cyber Spending Set to Surge Amid Rising Attacks on Military Systems
CRA Reporting Rules Take Effect: How to Ensure Your Organization is Ready
Researchers Build WeChat Zero-Click Worm Hijacking Phones via Calls
NHIs Now the Number One Corporate Entry Point for Hackers
Understanding Frontier AI Defense: What Cyber and IT Leads Need to Know
Human Risk in Cybersecurity: Protecting Your Organization Beyond Technology
Same Front Door, New Visitors: Securing Humans and AI Agents at the Browser
Financial Services Cyber Resilience: Stress Testing Third Parties Before Attackers Do
How To Enhance Security Operations with AI-Powered Defenses
How to Manage Enterprise Cyber Resilience in the Age of AI
How Faster Cyber-Attacks Are Reshaping Enterprise Cybersecurity Strategies
Researchers Claim First Fully Agentic Ransomware: JadePuffer
AI is Already Powering Cyber-Attacks. Can it Power Cyber Defense?
Google Cloud's New CISO Chris Betz on Integrating AI in Cyber Defenses
How World Cup Password Trends Can Increase Active Directory Risk
New CISA Guide Helps Agencies Adopt SASE For Zero Trust
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
