• 4 minuti
  • Pubblicato

Zero-day flaw in TP-Link Tapo C200 exposed homes to surveillance

Barbara Carminati Autrice di cybersecurity e privacy QWERTYmag

Scritto da Barbara Carminati

Zero-day flaw in TP-Link Tapo C200 exposed homes to surveillance QWERTYmag © www.qwertymag.it
Zero-day flaw in TP-Link Tapo C200 exposed homes to surveillance © www.qwertymag.it

A zero-day vulnerability in TP-Link Tapo C200 cameras let attackers bypass authentication and access live video. Patches have been released, but a third critical flaw is still under review, raising new concerns for connected home security.

For owners of the TP-Link Tapo C200 camera, the risk of someone spying inside their home was not just theoretical. A zero-day vulnerability allowed attackers to bypass authentication and take control of the device's most sensitive features.

Researchers at OPSWAT found two serious flaws in the Tapo C200, a camera often used for baby monitoring and small office security. The most severe, CVE-2026-15315, let anyone on the same network replay a session and gain full administrative access-no password required. With this access, an attacker could watch live video, view stored recordings, and change device settings, turning a security camera into a privacy risk.

The second flaw, CVE-2026-15316, allowed attackers to crash the camera's HTTPS service by sending malformed encrypted credentials during setup. This denial-of-service attack could take the camera offline, leaving users without surveillance when they might need it most.

Le vulnerabilità CVE-2026-15315 e CVE-2026-15316 hanno evidenziato come la sicurezza dei dispositivi IoT debba essere valutata non solo rispetto all'accesso remoto, ma anche all'esposizione nel perimetro di rete locale. La tempestiva collaborazione tra ricercatori e produttore ha permesso di ridurre la finestra di rischio per gli utenti finali.

TP-Link released firmware update V5_1.4.6 on August 18 to fix both vulnerabilities. But the issue isn't closed. OPSWAT and TP-Link are still working on a third, undisclosed zero-day flaw, which researchers say is critical. According to OPSWAT, this bug could let an attacker fully compromise the camera and use it to attack other devices on the same network. Dahvid Schloss of Suzu Labs suggested the exploit might involve command injection or a memory-safety bug, possibly allowing code execution as root-something more common in older IoT devices than in newer ones.

Schloss pointed out that attackers would need to be on the same network as the camera for the exploit to work. "If someone's made it that far into your network, they're not after the baby monitor," he said. Still, if the camera is set up with port forwarding to the internet-a less common setup for home users-the risk increases significantly.

This case follows a pattern seen in other recent incidents, like the ScreenConnect vulnerability, where slow patching left many systems open to attack. Connected devices, especially those aimed at homes and small businesses, remain attractive targets for attackers who exploit overlooked flaws and weak default settings.

Technical vulnerabilities and TP-Link's response

The main problems were in how the camera handled authentication sessions and validated encrypted data. With CVE-2026-15315, an attacker could replay a captured authentication request and get admin access without knowing the user's password. This allowed changes to device settings and access to all restricted features, including live and recorded video.

The second flaw, CVE-2026-15316, affected the onboarding process. Sending malformed encrypted data could crash the camera's HTTPS service, causing an outage and leaving the area unwatched.

TP-Link has released a patch, but the ongoing investigation into a third critical vulnerability suggests these devices still have a broad and underestimated attack surface.

Implications for home and business security

The ease with which an attacker can take over a home security camera-even just from the local network-raises questions about trust in consumer IoT devices. If remote access is enabled through port forwarding, the risk of compromise rises sharply, turning a simple camera into a possible entry point for wider attacks on home or business networks.

The TP-Link Tapo C200 case shows that connected device security can't rely on reactive patches or default settings. Users need to update firmware promptly and review network configurations, while manufacturers must strengthen development and testing, especially for devices meant to protect privacy and safety. In a market where speed often outweighs robustness, each new vulnerability is a warning that can't be ignored.

For the European market, compliance with data security and privacy rules-such as those from AGCOM-is becoming central when evaluating smart home devices. The Tapo C200, designed for home and small office monitoring, highlights the need for even consumer products to meet high standards for cybersecurity and data protection.

Articoli correlati