Skip to content
Zero-Day Flaw in TP

Zero-Day Flaw in TP

Infosecurity-Magazine September 16, 2026

Security researchers have released details of two zero-day vulnerabilities found in TP-Link security cameras commonly used in and small offices, one of which could enable attackers to spy on users.

OPSWAT said the bugs affect the TP-Link Tapo C200 camera often used for baby/pet monitoring, security and SOHO business security.

CVE-2026-15315 and CVE-2026-15316 were patched by the Chinese manufacturer in firmware version V5_1.4.6 released on August 18.

CVE-2026-15315 is an authentication bypass through replay which could allow an attacker with network access to the camera to obtain a valid administrative session without knowing or recovering the user's password.

“The resulting administrative access enables the attacker to invoke privileged management functions, modify device configuration and perform operations that would normally require authorized administrator access,” OPSWAT explained.

“This access may also expose privacy-sensitive camera functionality, including live video streams and stored recordings, enabling unauthorized surveillance of footage captured by the affected device.”

Dahvid Schloss, COO at Suzu Labs, said the high-severity flaw is less dangerous than it sounds, because an attacker would have to be on the same network as the camera in order for it to work.

“If someone's made it that far into your network, they're not after the baby monitor,” he added. “Now, if the camera was port-forwarded to the internet, that's a bigger design issue and probably should be a concern, but not a common setup for the everyday user.”

CVE-2026-15316 is a denial-of-service vulnerability which impacts the camera's onboarding configuration flow. Encrypted credential data needs to be validated before being passed to cryptographic and configuration-processing routines.

“An unauthenticated attacker with network access to the camera can submit an oversized encrypted credential value,” OPSWAT wrote. “When the malformed data reaches the vulnerable processing path, it can cause the camera's HTTPS service to crash, resulting in a denial-of-service condition.”

A Third Vulnerability Could Be Worse

While both of the published vulnerabilities are high severity, OPSWAT is currently working with the camera-maker on an additional zero day it found, which it rates as critical.

“It could allow an attacker to fully compromise the camera and use the compromised device as a foothold within the network,” OPSWAT claimed.

“I would guess the exploit would be a command injection or a memory-safety bug in the same management service, chained behind that auth bypass to get code execution as root, where they then dropped a static binary to return a shell on the device whose firmware ships with almost no tooling,” said Suzu Labs’ Schloss.

“That attack chain isn't uncommon on cheap, older consumer IoT devices where security wasn't top of mind, but if that's the case here, seeing it hold up on a modern TP-Link device would be a bit of a blast from the past.”

Details will be shared once a fix is available.

Image credit: tinhkhuong / Shutterstock.com

US Government Ordered to Urgently Patch Apple Zero-Day Bugs News 12 September 2023

US Government Ordered to Urgently Patch Apple Zero-Day Bugs

#BSidesBelfast: Focus More on Common Attacks, Less on Zero-Days News 31 October 2019

#BSidesBelfast: Focus More on Common Attacks, Less on Zero-Days

Microsoft Fixes 400 Flaws on August Patch Tuesday News 12 August 2026

Microsoft Fixes 400 Flaws on August Patch Tuesday

Microsoft Fixes 200 CVEs in June Patch Tuesday News 10 June 2026

Microsoft Fixes 200 CVEs in June Patch Tuesday

Microsoft Reports Severe Zero-Day Flaw in On-Prem Exchange Servers News 15 May 2026

Microsoft Reports Severe Zero-Day Flaw in On-Prem Exchange Servers

What’s Hot on Infosecurity Magazine?

Microsoft Releases Emergency Patch to Fix RDS Vulnerability

Revolut Confirms Data Breach Through Fake Government Requests

Hackers Exploit Maximum Severity Flaw in GitLab

OpenAI Agent Swarm Hacks RubyGems Package Manager

Human Attacker Hits Machine-Speed Exploitation of Marimo RCE

Malicious Twitch Extension Exposes 31,000 Users' OAuth Tokens

Anthropic Reveals Yet Another Cybersecurity Incident

FBI Publishes First-Ever Cyber Strategy, With Focus on Disrupting Threat Actors

Defense Cyber Spending Set to Surge Amid Rising Attacks on Military Systems

CRA Reporting Rules Take Effect: How to Ensure Your Organization is Ready

Researchers Build WeChat Zero-Click Worm Hijacking Phones via Calls

NHIs Now the Number One Corporate Entry Point for Hackers

Understanding Frontier AI Defense: What Cyber and IT Leads Need to Know

Human Risk in Cybersecurity: Protecting Your Organization Beyond Technology

Same Front Door, New Visitors: Securing Humans and AI Agents at the Browser

Financial Services Cyber Resilience: Stress Testing Third Parties Before Attackers Do

How To Enhance Security Operations with AI-Powered Defenses

How to Manage Enterprise Cyber Resilience in the Age of AI

How Faster Cyber-Attacks Are Reshaping Enterprise Cybersecurity Strategies

Researchers Claim First Fully Agentic Ransomware: JadePuffer

AI is Already Powering Cyber-Attacks. Can it Power Cyber Defense?

Google Cloud's New CISO Chris Betz on Integrating AI in Cyber Defenses

How World Cup Password Trends Can Increase Active Directory Risk

New CISA Guide Helps Agencies Adopt SASE For Zero Trust