CVE-2026-15315

Published Aug 18, 2026

Last updated 16 days ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-15315 is an authentication bypass vulnerability found in TP-Link Tapo C120 v1 and C200 v5 smart cameras. This flaw exists within the login authentication verification module, specifically in the local HTTPS management interface operating on port 443. Researchers discovered that the camera's challenge-response authentication process could be circumvented by replaying a value the device originally returned during an authentication exchange. An attacker on the local network can exploit this weakness in challenge parameter validation to obtain valid administrative session tokens without needing to know or recover the user's password. Successful exploitation grants unauthorized administrative access, enabling the attacker to execute privileged management functions, modify device configurations, and potentially access privacy-sensitive features like live video streams and stored recordings. TP-Link addressed this vulnerability in firmware version V5_1.4.6, released on August 18, 2026.

Description
Tapo C120 v1 and C200 v5 contain an improper authentication vulnerability within the login authentication verification module. An attacker on the local network can exploit weaknesses in challenge parameter validation to bypass normal authentication controls and obtain administrative session tokens. Successful exploitation may allow an attacker to subsequently execute privileged management actions, enable unauthorized administrative access and temporary disruption of device services, resulting in a denial-of-service (DoS) condition.
Source
f23511db-6c3e-4e32-a477-6aa17d310630
NVD status
Analyzed
Products
tapo_c120_firmware, tapo_c200_firmware

Risk scores

CVSS 4.0

Type
Secondary
Base score
8.7
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
HIGH

CVSS 3.1

Type
Primary
Base score
8.8
Impact score
5.9
Exploitability score
2.8
Vector string
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

f23511db-6c3e-4e32-a477-6aa17d310630
CWE-287

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

1

  1. TP-Link Tapo: Κενό ασφαλείας, επιτρέπει τον οποιοδήποτε να δει εικόνα καμερών [και στην Ελλάδα] Εντοπίστηκαν σοβαρές ευπάθειες ασφαλείας (CVE-2026-15315, CVE-2026-15316) στι

    @techmaniacsgr

    19 Sept 2026

    116 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. Vulnerabilidades 0-day en cámaras TP-Link permiten espiar usuarios Se han detectado dos vulnerabilidades de día cero (CVE-2026-15315 y CVE-2026-15316) en las cámaras inteligentes TP-Link Tapo C200 https://t.co/3n9cxFlezP

    @elhackernet

    17 Sept 2026

    12747 Impressions

    53 Retweets

    141 Likes

    65 Bookmarks

    0 Replies

    2 Quotes

  3. 🔴 TP-Link Tapo C200 model güvenlik kamerası ürününde iki güvenlik açığı tespit edildi! CVE-2026-15315: Aynı ağdaki kimlik doğrulanmamış saldırgan, authentication mekanizmasını aşarak yönetici oturumu elde edebiliyor. Bu durum kamera görüntülerine ve yö

    @ridvanyagli

    17 Sept 2026

    285 Impressions

    2 Retweets

    3 Likes

    1 Bookmark

    2 Replies

    0 Quotes

  4. ❗ TP-Link Tapo C200 kameralarda 0-day açığı! CVE-2026-15315 ve CVE-2026-15316, aynı ağdaki saldırganların kimlik doğrulamayı aşmasına veya kamera hizmetini bozmasına yol açabiliyor. Açıklar V51.4.6 firmware’inde düzeltildi. #CyberSecurity #IoT https://t.co

    @KubbeSiber

    16 Sept 2026

    9 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. برای دوربین Tp-link مدل Tapo ، دو آسیب پذیری با کدهای شناسایی CVE-2026-15315 و CVE-2026-15316 منتشر شده است ، این آسیب پذیری ها ، از نوع authentication bypass بوده و به هکرها ، امکان لاگ

    @EthicalSafe

    16 Sept 2026

    5 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. Urgent for anyone running TP-Link Tapo C200 cameras: two zero-day vulnerabilities—an auth bypass (CVE-2026-15315) and DoS flaw (CVE-2026-15316)—were patched in firmware V5_1.4.6 on August 18, 2026. Attackers sharing your network could access your camera’s admin functions or

    @dailytechonx

    16 Sept 2026

    58 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations