Researchers from OPSWAT have uncovered two severe zero-day vulnerabilities in TP-Link security cameras, specifically the Tapo C200 model commonly used in homes and small offices. The first vulnerability, identified as CVE-2026-15315, allows attackers with network access to bypass authentication through a replay attack, potentially granting unauthorized administrative access to the camera. This could enable attackers to alter device configurations and access live video feeds or stored recordings, posing a significant privacy risk.
The second vulnerability, CVE-2026-15316, involves a denial-of-service issue in the camera's onboarding configuration. Attackers can exploit this flaw by submitting an oversized encrypted credential, causing the camera's HTTPS service to crash. Although both vulnerabilities are serious, TP-Link has issued a firmware update, V5_1.4.6, on August 18 to address these issues.
Dahvid Schloss, COO at Suzu Labs, suggests that while the authentication bypass is concerning, it requires the attacker to be on the same network as the camera, which is less likely in typical home setups. However, if the camera is exposed to the internet, it poses a greater threat. OPSWAT is also working on an additional zero-day vulnerability that could potentially allow full device compromise, indicating that security teams should remain vigilant as more details are expected to be released once a fix is confirmed.

