AI description
CVE-2026-15315 is an authentication bypass vulnerability found in TP-Link Tapo C120 v1 and C200 v5 smart cameras. This flaw exists within the login authentication verification module, specifically in the local HTTPS management interface operating on port 443. Researchers discovered that the camera's challenge-response authentication process could be circumvented by replaying a value the device originally returned during an authentication exchange. An attacker on the local network can exploit this weakness in challenge parameter validation to obtain valid administrative session tokens without needing to know or recover the user's password. Successful exploitation grants unauthorized administrative access, enabling the attacker to execute privileged management functions, modify device configurations, and potentially access privacy-sensitive features like live video streams and stored recordings. TP-Link addressed this vulnerability in firmware version V5_1.4.6, released on August 18, 2026.
- Description
- Tapo C120 v1 and C200 v5 contain an improper authentication vulnerability within the login authentication verification module. An attacker on the local network can exploit weaknesses in challenge parameter validation to bypass normal authentication controls and obtain administrative session tokens. Successful exploitation may allow an attacker to subsequently execute privileged management actions, enable unauthorized administrative access and temporary disruption of device services, resulting in a denial-of-service (DoS) condition.
- Source
- f23511db-6c3e-4e32-a477-6aa17d310630
- NVD status
- Analyzed
- Products
- tapo_c120_firmware, tapo_c200_firmware
CVSS 4.0
- Type
- Secondary
- Base score
- 8.7
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- HIGH
CVSS 3.1
- Type
- Primary
- Base score
- 8.8
- Impact score
- 5.9
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- HIGH
- f23511db-6c3e-4e32-a477-6aa17d310630
- CWE-287
Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.
- Hype score
1
TP-Link Tapo: Κενό ασφαλείας, επιτρέπει τον οποιοδήποτε να δει εικόνα καμερών [και στην Ελλάδα] Εντοπίστηκαν σοβαρές ευπάθειες ασφαλείας (CVE-2026-15315, CVE-2026-15316) στι
@techmaniacsgr
19 Sept 2026
116 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Vulnerabilidades 0-day en cámaras TP-Link permiten espiar usuarios Se han detectado dos vulnerabilidades de día cero (CVE-2026-15315 y CVE-2026-15316) en las cámaras inteligentes TP-Link Tapo C200 https://t.co/3n9cxFlezP
@elhackernet
17 Sept 2026
12747 Impressions
53 Retweets
141 Likes
65 Bookmarks
0 Replies
2 Quotes
🔴 TP-Link Tapo C200 model güvenlik kamerası ürününde iki güvenlik açığı tespit edildi! CVE-2026-15315: Aynı ağdaki kimlik doğrulanmamış saldırgan, authentication mekanizmasını aşarak yönetici oturumu elde edebiliyor. Bu durum kamera görüntülerine ve yö
@ridvanyagli
17 Sept 2026
285 Impressions
2 Retweets
3 Likes
1 Bookmark
2 Replies
0 Quotes
❗ TP-Link Tapo C200 kameralarda 0-day açığı! CVE-2026-15315 ve CVE-2026-15316, aynı ağdaki saldırganların kimlik doğrulamayı aşmasına veya kamera hizmetini bozmasına yol açabiliyor. Açıklar V51.4.6 firmware’inde düzeltildi. #CyberSecurity #IoT https://t.co
@KubbeSiber
16 Sept 2026
9 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
برای دوربین Tp-link مدل Tapo ، دو آسیب پذیری با کدهای شناسایی CVE-2026-15315 و CVE-2026-15316 منتشر شده است ، این آسیب پذیری ها ، از نوع authentication bypass بوده و به هکرها ، امکان لاگ
@EthicalSafe
16 Sept 2026
5 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Urgent for anyone running TP-Link Tapo C200 cameras: two zero-day vulnerabilities—an auth bypass (CVE-2026-15315) and DoS flaw (CVE-2026-15316)—were patched in firmware V5_1.4.6 on August 18, 2026. Attackers sharing your network could access your camera’s admin functions or
@dailytechonx
16 Sept 2026
58 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:tp-link:tapo_c120_firmware:*:*:*:*:*:*:*:*",
"matchCriteriaId": "5064D430-3839-415B-A046-4F2AE658EB76",
"versionEndExcluding": "1.9.3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
},
{
"cpeMatch": [
{
"criteria": "cpe:2.3:h:tp-link:tapo_c120:-:*:*:*:*:*:*:*",
"matchCriteriaId": "0BA06003-EB4D-4836-9D99-15E4BDE9E492",
"vulnerable": false
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:tp-link:tapo_c200_firmware:*:*:*:*:*:*:*:*",
"matchCriteriaId": "44FE2CEB-2F2C-4230-AD56-0F1BD055233C",
"versionEndExcluding": "1.4.6",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
},
{
"cpeMatch": [
{
"criteria": "cpe:2.3:h:tp-link:tapo_c200:5.0:*:*:*:*:*:*:*",
"matchCriteriaId": "8CF02BAF-93FA-476A-BC2E-B44419D42A02",
"vulnerable": false
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
}
]