TP-Link Camera Flaws Could Let Attackers Watch Your Footage
Security researchers at OPSWAT have disclosed two vulnerabilities affecting the TP-Link Tapo C200, a camera widely used for home security, baby and pet monitoring, and small office surveillance. TP-Link has already released a fix in firmware version V5_1.4.6, published on 18 August.
The more serious flaw, CVE-2026-15315, is an authentication bypass that could let an attacker with access to the same network gain administrative control of the camera without needing the password. This could allow them to change settings or view live and recorded footage. Experts note the real-world risk is limited because the attacker needs network access first, though cameras exposed directly to the internet would be at greater risk. The second flaw, CVE-2026-15316, is a denial-of-service issue that could let an unauthenticated attacker crash the camera's HTTPS service by sending malformed data during setup. OPSWAT is also working with TP-Link on a third, more critical vulnerability not yet fully disclosed.
Both confirmed flaws are rated high severity, and businesses using these devices should treat the update as a priority, particularly if cameras are accessible beyond a trusted local network.