CVE-2026-15316
Denial-of-Service via Oversized Encrypted Credential Input in TP-Link Tapo C200
Description
An improper input validation vulnerability in the configuration service for processing encrypted credential data has been identified in Tapo C200 v5. An attacker can send oversized crypted ciphertext values that may trigger exception handling failures, due to insufficient validation, causing the affected device to crash or restart. Successful exploitation may temporarily disrupt HTTPS management and monitoring functionality, resulting in a denial-of-service (DoS) condition until the service recovers.
In plain language
AI Act nowTapo C200 v5 cameras running firmware earlier than 1.4.6 can be forced to restart by someone on your local network, disrupting camera monitoring and management.
Unauthenticated adjacent-network denial of service in the Tapo C200 v5 configuration service: oversized encrypted credential input triggers exception-handling failures and restarts the device.
What to do now
- Check whether you use a Tapo C200 v5 and record its installed firmware version in the Tapo app or camera management page.
- Update affected cameras to firmware 1.4.6; for the v5 release, install V5_1.4.6 Build 260709 Rel.27675n.
- Until updated, keep the camera configuration service accessible only from trusted local network devices.
- After updating, confirm the camera stays online and HTTPS management access works normally.
CVSS Vector Breakdown
AV:AAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:NConfidentialityI:NIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-15316 and every CVE in our database. Create a free account — no credit card required.
Create Free Account