Skip to content
Two Critical Vulnerabilities Discovered in TP-Link Tapo Cameras

Two Critical Vulnerabilities Discovered in TP-Link Tapo Cameras

First seen 16 Sep 2026, 10:56 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 16, 2026 at 11:54 UTC

OPSWAT has identified two critical vulnerabilities in the TP-Link Tapo C200 smart security camera, tracked as CVE-2026-15315 and CVE-2026-15316. CVE-2026-15315 allows an unauthenticated attacker with network access to bypass authentication and gain administrative access, potentially enabling unauthorized surveillance. CVE-2026-15316 is a denial-of-service vulnerability that can crash the camera's HTTPS service during Wi-Fi onboarding. Both vulnerabilities were patched in firmware version V5_1.4.6, released on August 18, 2026. Users are urged to update their devices immediately to mitigate risks. The vulnerabilities were reported to TP-Link on April 16, 2026, and confirmed by the manufacturer on July 10, 2026. OPSWAT is also investigating a third critical vulnerability that could allow full device compromise.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-04-16
Vulnerabilities reported to TP-Link
OPSWAT researchers Khoi Tran and Thai Do reported the vulnerabilities to TP-Link for remediation.
OPSWAT
2026-07-10
TP-Link confirms vulnerabilities
TP-Link acknowledged the reported vulnerabilities and began working on fixes.
OPSWAT
2026-08-18
Firmware patch released
TP-Link released firmware version V5_1.4.6 to address CVE-2026-15315 and CVE-2026-15316.
Infosecurity-Magazine
2026-08-18
CVE-2026-15315 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-18
CVE-2026-15316 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-16
Public disclosure of vulnerabilities
OPSWAT publicly disclosed the vulnerabilities, providing details on their nature and impact.
Infosecurity-Magazine

More articles in this cluster (2)

Following this threat?

Track Opswat and CVE-2026-15315 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed