Zero-Day Flaw in TP-Link Cameras Enables Eavesdropping
OPSWAT disclosed two zero-day vulnerabilities in TP-Link Tapo C200 cameras: CVE-2026-15315 allows authentication bypass via session replay and access to video and recordings, while CVE-2026-15316 causes denial of service. Both were fixed in firmware V5_1.4.6 on August 18; researchers are working on another critical flaw.
- CVE-2026-15315 — replay-based auth bypass granting admin rights
- CVE-2026-15316 — denial of service via an overflowing credential value
- Fixes released in firmware V5_1.4.6 on August 18
- OPSWAT is working on another critical unpatched vulnerability
Read next
Security