Two popular TP-Link Tapo home security cameras, the C200 and C120, had a security flaw that could let anyone on your Wi-Fi take over the camera, and the C200 had a second flaw that could crash it, but TP-Link has already released firmware updates that fix both problems. The issues were found by security firm OPSWAT and are tracked as CVE-2026-15315 and CVE-2026-15316. If you own a Tapo C200 hardware version V5 or a Tapo C120 hardware version V1, the fix is simple: update your camera’s firmware through the Tapo app and make sure it matches TP-Link’s latest versions.
What went wrong inside the Tapo C200 and C120
The more serious flaw, CVE-2026-15315, is an “unauthenticated administrative authentication bypass,” which is a long way of saying an attacker could skip the login step and grab an administrator session token without knowing the password. With that token, they would be able to control the affected camera and view its video stream as if they had logged in normally. TP-Link rated this issue 8.7 High on its own advisory, which reflects how much access that token gives an attacker.
The second flaw, CVE-2026-15316, affects only the Tapo C200 V5 and is a denial-of-service bug that lets an attacker crash or restart the camera by sending oversized values. This one does not give anyone access to your video, but it can knock the camera offline. TP-Link rated it 7.1 High, since it can still disrupt security monitoring and leave a blind spot if your camera keeps rebooting.
Only two models and only on your local network
According to TP-Link’s security advisory, the only affected models are Tapo C120 hardware version V1 and Tapo C200 hardware version V5. No other Tapo cameras or hardware versions are mentioned in the advisory, and TP-Link’s own FAQ calls out only those two. Some early coverage focused only on the C200, but TP-Link’s documentation clearly lists both the C120 V1 and C200 V5 as vulnerable.
There is also an important limit on what an attacker can do with these bugs: they must already be on the same local network as the camera. This is not an attack that lets random hackers on the internet spy on you from anywhere. To exploit either flaw, the attacker needs to be connected to the same Wi-Fi or wired network that your Tapo camera is on.
Why “same Wi-Fi” still matters
Needing to be on the same network might sound like a small risk, but for many homes it is still a real concern. If you share Wi-Fi with roommates, neighbors in a shared building, or other tenants on a common network, anyone on that network could try to use these flaws. Guest networks can also be a weak point if they are not fully isolated from your main smart home devices.
Another common risk is a device already on your network that has been compromised in some other way. An older router, a cheap smart plug with weak security, or a malware-infected laptop can give an attacker a foothold inside your network. Once they are “inside,” these Tapo flaws would let them move from simply being on your Wi-Fi to taking control of the C120 V1 or C200 V5, unless you have installed the fixed firmware.
How TP-Link and OPSWAT handled the flaws
OPSWAT first reported the vulnerabilities to TP-Link on April 16, 2026. TP-Link confirmed the issues on July 10, 2026, after reviewing the report. The official CVE identifiers, CVE-2026-15315 and CVE-2026-15316, were assigned on August 13, 2026, which is how security researchers track and reference specific bugs.
TP-Link released firmware version V5_1.4.6 for the C200 V5, which fixes both vulnerabilities, on August 18, 2026, alongside its advisory. The C120 V1 fix had already shipped that June. OPSWAT then published its public write-up on September 15, 2026. There is no information in the disclosures that these flaws were used in real-world attacks, but the updates are available now, and TP-Link recommends installing them as soon as possible.
One caveat worth knowing: OPSWAT says its researchers found more than the two flaws it has published. In its write-up it notes that the same pair of researchers identified a critical issue that could let an attacker fully compromise the camera and use it as a foothold inside the network, and that those findings are still under coordinated disclosure with TP-Link. No fix for that one has been released yet, and details are being held back until there is.
The firmware versions that fix the problem
TP-Link’s advisory lists very specific firmware versions that contain the fixes. For the Tapo C120 hardware version V1, the fixed firmware is version 1.9.3 Build 260521. For the Tapo C200 hardware version V5, the fixed firmware is version V5_1.4.6 Build 260709 Rel.27675n. If your camera is running those or later versions, you are protected against the flaws TP-Link lists for that model.
If you are not sure which hardware version you have, you can check it in the Tapo app or on the label on the camera itself. Only C120 V1 and C200 V5 are listed as affected, so a different hardware version of those models is not in TP-Link’s advisory for these particular flaws. Still, checking and updating the firmware on any internet-connected camera is a good habit.
What Tapo camera owners should do right now
To protect yourself, the main step is to open the Tapo app and confirm your camera’s firmware version. Go to each Tapo C120 and C200 you own in the app, look for the firmware or device information section, and compare the version number against the fixed versions: 1.9.3 Build 260521 for Tapo C120 V1, and V5_1.4.6 Build 260709 Rel.27675n for Tapo C200 V5. If your camera shows an update waiting, install it right away and let the camera reboot.
After updating, it is also smart to review who and what is on your Wi-Fi. Make sure your main network uses a strong password, limit access on shared or guest networks, and remove devices you do not recognize. The two Tapo flaws OPSWAT has published are patched, and a third critical one from the same research is still waiting on a TP-Link fix, so staying on top of firmware updates and basic Wi-Fi hygiene goes a long way toward keeping your home cameras from becoming an easier target for anyone who ends up on your network.
View the original press release.