www.opswat.com Two Critical Vulnerabilities Discovered in TP-Link Tapo Cameras
Article Content
- •Two critical vulnerabilities found in TP-Link Tapo C200 cameras.
- •CVE-2026-15315 allows authentication bypass; CVE-2026-15316 causes denial-of-service.
- •Firmware update V5_1.4.6 released on August 18, 2026, to patch both vulnerabilities.
OPSWAT has identified two critical vulnerabilities in the TP-Link Tapo C200 smart security camera, tracked as CVE-2026-15315 and CVE-2026-15316. CVE-2026-15315 allows an unauthenticated attacker with network access to bypass authentication and gain administrative access, potentially enabling unauthorized surveillance. CVE-2026-15316 is a denial-of-service vulnerability that can crash the camera's HTTPS service during Wi-Fi onboarding. Both vulnerabilities were patched in firmware version V5_1.4.6, released on August 18, 2026. Users are urged to update their devices immediately to mitigate risks. The vulnerabilities were reported to TP-Link on April 16, 2026, and confirmed by the manufacturer on July 10, 2026. OPSWAT is also investigating a third critical vulnerability that could allow full device compromise.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Opswat and CVE-2026-15315 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…