CVE-2026-15315 and CVE-2026-15316 were patched in TP-Link camera firmware version V5_1.4.6 released on August 18, but security researchers warn an additional, still-unpatched zero day may be more serious.
CVE-2026-15315: authentication bypass through replay
OPSWAT disclosed that CVE-2026-15315 is an authentication bypass through replay that affects TP-Link Tapo C200 cameras, a model "often used for baby/pet monitoring, home security and SOHO business security." The vendor-patched advisory says the flaw could allow "an attacker with network access to the camera to obtain a valid administrative session without knowing or recovering the user's password."
OPSWAT spelled out the consequences of that access: "The resulting administrative access enables the attacker to invoke privileged management functions, modify device configuration and perform operations that would normally require authorized administrator access." The advisory further warns that such access "may also expose privacy-sensitive camera functionality, including live video streams and stored recordings, enabling unauthorized surveillance of footage captured by the affected device."
That exposure is the core privacy risk: an attacker who can obtain administrative rights via a replay attack can reach the same controls a legitimate administrator would, including viewing live streams and stored footage.
CVE-2026-15316: onboarding denial-of-service
OPSWAT also published CVE-2026-15316, a denial-of-service vulnerability that "impacts the camera's onboarding configuration flow." The advisory explains the technical cause: "Encrypted credential data needs to be validated before being passed to cryptographic and configuration-processing routines."
In practice, OPSWAT wrote, "An unauthenticated attacker with network access to the camera can submit an oversized encrypted credential value. When the malformed data reaches the vulnerable processing path, it can cause the camera's HTTPS service to crash, resulting in a denial-of-service condition." The result is a crashed HTTPS service during onboarding, preventing configuration and access until the device recovers or is rebooted.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleTP-Link firmware V5_1.4.6 (released August 18) and a still-unpatched critical zero day
The two vulnerabilities above were patched by TP-Link in firmware version V5_1.4.6 released on August 18. OPSWAT, which published the advisories, also said it is "currently working with the camera-maker on an additional zero day it found, which it rates as critical."
That third vulnerability, OPSWAT claimed, "could allow an attacker to fully compromise the camera and use the compromised device as a foothold within the network." Suzu Labs’ Dahvid Schloss offered a technical hypothesis on how such a chain might be assembled: "I would guess the exploit would be a command injection or a memory-safety bug in the same management service, chained behind that auth bypass to get code execution as root, where they then dropped a static binary to return a shell on the device whose firmware ships with almost no tooling."
Schloss added context about likelihood and reach: "The resulting administrative access enables the attacker to invoke privileged management functions, modify device configuration and perform operations that would normally require authorized administrator access," and cautioned that the attack pattern he described "isn't uncommon on cheap, older consumer IoT devices where security wasn't top of mind, but if that's the case here, seeing it hold up on a modern TP-Link device would be a bit of a blast from the past."
What this means for technologists, end users, and network operators
- Technologists and security teams: Confirm TP-Link Tapo C200 devices in inventories and, where possible, verify they are running firmware V5_1.4.6. Watch for follow-up advisories from OPSWAT and TP-Link about the critical zero day and any mitigation guidance.
- End users and home network operators: Be aware that the Tapo C200 is "often used for baby/pet monitoring, home security and SOHO business security." Dahvid Schloss noted a limiting factor: the auth-bypass exploit "would have to be on the same network as the camera," though he warned that if "the camera was port-forwarded to the internet, that's a bigger design issue and probably should be a concern."
- Network administrators and SOHO operators: Consider network segmentation and review port-forwarding rules for cameras; OPSWAT's advisory shows how network access can be a precondition for both the auth-bypass and the onboarding denial-of-service.
OPSWAT said the two published issues are high severity, and it will share further details about the critical zero day "once a fix is available." For now, the vendor-supplied patch (V5_1.4.6, August 18) is the immediate remediation on record; the more serious, still-unpatched vulnerability remains under coordinated disclosure.
Original story: https://www.infosecurity-magazine.com/news/zeroday-tplink-cameras/



