AI description
CVE-2026-15316 is an improper input validation vulnerability found in the configuration service of the TP-Link Tapo C200 camera, specifically affecting versions prior to V5_1.4.6. This flaw allows an attacker to send oversized encrypted credential data to the device. Due to insufficient validation, these malformed inputs can trigger exception handling failures, causing the affected camera to crash or restart. The successful exploitation of CVE-2026-15316 can temporarily disrupt the camera's HTTPS management and monitoring functionality, leading to a denial-of-service (DoS) condition until the service recovers. TP-Link addressed this issue in firmware version V5_1.4.6, released on August 18, 2026.
- Description
- An improper input validation vulnerability in the configuration service for processing encrypted credential data has been identified in Tapo C200 v5. An attacker can send oversized crypted ciphertext values that may trigger exception handling failures, due to insufficient validation, causing the affected device to crash or restart. Successful exploitation may temporarily disrupt HTTPS management and monitoring functionality, resulting in a denial-of-service (DoS) condition until the service recovers.
- Source
- f23511db-6c3e-4e32-a477-6aa17d310630
- NVD status
- Analyzed
- Products
- tapo_c200_firmware
CVSS 4.0
- Type
- Secondary
- Base score
- 7.1
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- HIGH
CVSS 3.1
- Type
- Primary
- Base score
- 6.5
- Impact score
- 3.6
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Severity
- MEDIUM
- f23511db-6c3e-4e32-a477-6aa17d310630
- CWE-20
Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.
- Hype score
1
TP-Link Tapo: Κενό ασφαλείας, επιτρέπει τον οποιοδήποτε να δει εικόνα καμερών [και στην Ελλάδα] Εντοπίστηκαν σοβαρές ευπάθειες ασφαλείας (CVE-2026-15315, CVE-2026-15316) στι
@techmaniacsgr
19 Sept 2026
116 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Vulnerabilidades 0-day en cámaras TP-Link permiten espiar usuarios Se han detectado dos vulnerabilidades de día cero (CVE-2026-15315 y CVE-2026-15316) en las cámaras inteligentes TP-Link Tapo C200 https://t.co/3n9cxFlezP
@elhackernet
17 Sept 2026
12747 Impressions
53 Retweets
141 Likes
65 Bookmarks
0 Replies
2 Quotes
❗ TP-Link Tapo C200 kameralarda 0-day açığı! CVE-2026-15315 ve CVE-2026-15316, aynı ağdaki saldırganların kimlik doğrulamayı aşmasına veya kamera hizmetini bozmasına yol açabiliyor. Açıklar V51.4.6 firmware’inde düzeltildi. #CyberSecurity #IoT https://t.co
@KubbeSiber
16 Sept 2026
9 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
برای دوربین Tp-link مدل Tapo ، دو آسیب پذیری با کدهای شناسایی CVE-2026-15315 و CVE-2026-15316 منتشر شده است ، این آسیب پذیری ها ، از نوع authentication bypass بوده و به هکرها ، امکان لاگ
@EthicalSafe
16 Sept 2026
5 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Urgent for anyone running TP-Link Tapo C200 cameras: two zero-day vulnerabilities—an auth bypass (CVE-2026-15315) and DoS flaw (CVE-2026-15316)—were patched in firmware V5_1.4.6 on August 18, 2026. Attackers sharing your network could access your camera’s admin functions or
@dailytechonx
16 Sept 2026
58 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:tp-link:tapo_c200_firmware:*:*:*:*:*:*:*:*",
"matchCriteriaId": "44FE2CEB-2F2C-4230-AD56-0F1BD055233C",
"versionEndExcluding": "1.4.6",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
},
{
"cpeMatch": [
{
"criteria": "cpe:2.3:h:tp-link:tapo_c200:5.0:*:*:*:*:*:*:*",
"matchCriteriaId": "8CF02BAF-93FA-476A-BC2E-B44419D42A02",
"vulnerable": false
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
}
]