CVE-2026-15316

Published Aug 18, 2026

Last updated 16 days ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-15316 is an improper input validation vulnerability found in the configuration service of the TP-Link Tapo C200 camera, specifically affecting versions prior to V5_1.4.6. This flaw allows an attacker to send oversized encrypted credential data to the device. Due to insufficient validation, these malformed inputs can trigger exception handling failures, causing the affected camera to crash or restart. The successful exploitation of CVE-2026-15316 can temporarily disrupt the camera's HTTPS management and monitoring functionality, leading to a denial-of-service (DoS) condition until the service recovers. TP-Link addressed this issue in firmware version V5_1.4.6, released on August 18, 2026.

Description
An improper input validation vulnerability in the configuration service for processing encrypted credential data has been identified in Tapo C200 v5.  An attacker can send oversized crypted ciphertext values that may trigger exception handling failures, due to insufficient validation, causing the affected device to crash or restart. Successful exploitation may temporarily disrupt HTTPS management and monitoring functionality, resulting in a denial-of-service (DoS) condition until the service recovers.
Source
f23511db-6c3e-4e32-a477-6aa17d310630
NVD status
Analyzed
Products
tapo_c200_firmware

Risk scores

CVSS 4.0

Type
Secondary
Base score
7.1
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
HIGH

CVSS 3.1

Type
Primary
Base score
6.5
Impact score
3.6
Exploitability score
2.8
Vector string
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Severity
MEDIUM

Weaknesses

f23511db-6c3e-4e32-a477-6aa17d310630
CWE-20

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

1

  1. TP-Link Tapo: Κενό ασφαλείας, επιτρέπει τον οποιοδήποτε να δει εικόνα καμερών [και στην Ελλάδα] Εντοπίστηκαν σοβαρές ευπάθειες ασφαλείας (CVE-2026-15315, CVE-2026-15316) στι

    @techmaniacsgr

    19 Sept 2026

    116 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. Vulnerabilidades 0-day en cámaras TP-Link permiten espiar usuarios Se han detectado dos vulnerabilidades de día cero (CVE-2026-15315 y CVE-2026-15316) en las cámaras inteligentes TP-Link Tapo C200 https://t.co/3n9cxFlezP

    @elhackernet

    17 Sept 2026

    12747 Impressions

    53 Retweets

    141 Likes

    65 Bookmarks

    0 Replies

    2 Quotes

  3. ❗ TP-Link Tapo C200 kameralarda 0-day açığı! CVE-2026-15315 ve CVE-2026-15316, aynı ağdaki saldırganların kimlik doğrulamayı aşmasına veya kamera hizmetini bozmasına yol açabiliyor. Açıklar V51.4.6 firmware’inde düzeltildi. #CyberSecurity #IoT https://t.co

    @KubbeSiber

    16 Sept 2026

    9 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. برای دوربین Tp-link مدل Tapo ، دو آسیب پذیری با کدهای شناسایی CVE-2026-15315 و CVE-2026-15316 منتشر شده است ، این آسیب پذیری ها ، از نوع authentication bypass بوده و به هکرها ، امکان لاگ

    @EthicalSafe

    16 Sept 2026

    5 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. Urgent for anyone running TP-Link Tapo C200 cameras: two zero-day vulnerabilities—an auth bypass (CVE-2026-15315) and DoS flaw (CVE-2026-15316)—were patched in firmware V5_1.4.6 on August 18, 2026. Attackers sharing your network could access your camera’s admin functions or

    @dailytechonx

    16 Sept 2026

    58 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations