TP-Link Tapo C120 and C200 Security Flaws: Update Your Camera Now

Two high-severity security flaws affect specific hardware versions of TP-Link’s Tapo C120 and C200 cameras. TP-Link has released patched firmware, so owners should check the model and hardware version in the Tapo app and install the latest update now.

The important limitation is that this is not a warning about every Tapo camera. TP-Link’s advisory identifies the Tapo C120 hardware version V1 and Tapo C200 hardware version V5. Older or different hardware revisions are not listed in this advisory, although keeping any connected camera current remains good practice.

Which Tapo cameras are affected?

  • Tapo C120 V1 — affected by CVE-2026-15315. Fixed in firmware 1.9.3 Build 260521 or later.
  • Tapo C200 V5 — affected by CVE-2026-15315 and CVE-2026-15316. Fixed in firmware V5_1.4.6 Build 260709 Rel.27675n or later.

If your camera has a different hardware version, do not install firmware intended for V1 or V5 manually. Use the Tapo app or the correct regional TP-Link support page so the device receives the package built for its exact model and revision.

What the security flaws could allow

CVE-2026-15315: authentication bypass

The first flaw affects the local login process. TP-Link says an attacker on the local network could exploit weak challenge-parameter validation, bypass normal authentication and obtain administrative session tokens without knowing the owner’s password.

That administrative access could allow unauthorized configuration changes and other privileged actions. OPSWAT, the research group that reported the issue, says access may also expose privacy-sensitive functions such as live video and stored recordings. The vulnerability has a CVSS 4.0 score of 8.7, rated High.

CVE-2026-15316: denial of service

The second flaw affects only the listed Tapo C200 V5 hardware. A nearby-network attacker could send an oversized encrypted credential value during the camera’s onboarding flow. Insufficient validation can make the HTTPS service crash or cause the camera to restart, temporarily interrupting management and monitoring. TP-Link rates this flaw High with a CVSS 4.0 score of 7.1.

Why local network access still matters

Both vulnerabilities require network access to the affected camera. That is an important boundary: the advisory does not describe a one-click attack that any random person on the internet can launch against every Tapo camera. Still, local-network access is not the same as harmless. A compromised computer, an untrusted guest device, weak Wi-Fi security or an exposed camera-management interface could put an attacker in the right position.

For a device that may watch living spaces, entrances or a child’s room, the safest response is to patch promptly rather than rely only on the local-network requirement.

How to update a Tapo C120 or C200

  • Open the Tapo app and tap your affected camera.
  • Open Device Settings, then select Firmware Update. TP-Link also allows you to check all devices from Me > Firmware Update.
  • Confirm the hardware version and install the newest firmware offered for that exact camera.
  • Keep the camera powered and connected during installation. Do not unplug it while the update is being applied.
  • After the camera restarts, return to Firmware Update and confirm that no newer version is pending.

TP-Link’s official firmware-update guide shows both update paths. Automatic Update can also be enabled, but it is still worth checking manually after a security advisory because staged rollouts may not reach every device at the same moment.

What to do after installing the patch

  • Do not expose the camera’s local management interface directly to the internet.
  • Use WPA2 or WPA3 security with a strong, unique Wi-Fi password.
  • Place cameras and other smart-home devices on a guest or IoT network when your router supports network isolation.
  • Review shared Tapo-account access and remove people or devices that no longer need it.
  • Enable automatic firmware updates, then periodically verify that the camera is still current.

A firmware patch closes the reported defects, but network segmentation and careful account management reduce the damage another compromised smart-home device could cause.

Should you replace the camera?

Not solely because of these two flaws. TP-Link has provided fixes for the affected hardware, and updating is the direct remedy. Replacement makes more sense if your camera can no longer receive security updates, repeatedly fails to update or no longer fits your privacy and monitoring needs.

If you are comparing current alternatives or accessories, you can browse Tapo cameras and accessories on Amazon. ReaderSpice participates in the Amazon Associates Program and may earn a commission from qualifying purchases at no additional cost to you.

Bottom line

Owners of Tapo C120 V1 and C200 V5 cameras should update immediately. The authentication-bypass flaw could grant an attacker on the local network administrative access, while the C200-specific input-validation flaw could interrupt camera management and monitoring. Check the hardware revision first, accept only the firmware offered for that exact device, and confirm the update completed successfully.

Sources

TP-Link security advisory for Tapo C120 and C200

OPSWAT technical disclosure of CVE-2026-15315 and CVE-2026-15316

TP-Link guide to updating Tapo and Kasa firmware

NIST NVD record for CVE-2026-15315

NIST NVD record for CVE-2026-15316