CVE-2026-15315
Unauthenticated Administrative Authentication Bypass via device_confirm Replay in TP-Link Tapo C120 and C200
Description
Tapo C120 v1 and C200 v5 contain an improper authentication vulnerability within the login authentication verification module. An attacker on the local network can exploit weaknesses in challenge parameter validation to bypass normal authentication controls and obtain administrative session tokens. Successful exploitation may allow an attacker to subsequently execute privileged management actions, enable unauthorized administrative access and temporary disruption of device services, resulting in a denial-of-service (DoS) condition.
In plain language
AI Act nowThis affects TP-Link Tapo C120 v1 and C200 v5 cameras: someone on your local network can take over the camera without its password, so update it promptly.
Unauthenticated administrative authentication bypass in Tapo C120 v1 and C200 v5 caused by replayable, weakly validated device_confirm challenge parameters.
What to do now
- Check each TP-Link Tapo C120 v1 and C200 v5 camera’s firmware version in the Tapo app or its device settings.
- Update Tapo C120 v1 to 1.9.3 Build 260521 or later, and Tapo C200 v5 to V5_1.4.6 Build 260709 Rel.27675n or later.
- Until every camera is updated, keep cameras on a private network and prevent guests or unknown devices from joining it.
CVSS Vector Breakdown
AV:AAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-15315 and every CVE in our database. Create a free account — no credit card required.
Create Free Account