Close Menu
MyAppsPlus

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Is Phone 4b secretly a CMF device? Carl Pei addresses rebranding rumors

    September 16, 2026

    Samsung starts rolling out Android 17 with One UI 9, confirms initial list of Galaxy devices

    September 16, 2026

    Waiting on your unlocked iPhone 18 Pro? Mint Mobile has an unlimited plan for just $15/mo right now — the perfect pairing

    September 16, 2026
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram
    MyAppsPlusMyAppsPlus
    Wednesday, September 16
    • Home
    • Breaking Tech
    • Apps & Software
    • AI & Automation
    • Android
    • iPhone & iOS
    • More
      • Reviews
      • How-To Guides
      • Deals & Discounts
      • Shop
    MyAppsPlus
    Home»Reviews»Watch out — TP-Link Tapo Camera vulnerabilities could let hackers spy inside homes, so patch now
    Reviews

    Watch out — TP-Link Tapo Camera vulnerabilities could let hackers spy inside homes, so patch now

    myappsplusBy myappsplusSeptember 16, 2026004 Mins Read
    Share Facebook Twitter Pinterest Copy Link LinkedIn Tumblr Email Telegram WhatsApp
    Follow Us
    Google News Flipboard
    Watch out — TP-Link Tapo Camera vulnerabilities could let hackers spy inside homes, so patch now
    Share
    Facebook Twitter LinkedIn Pinterest Email Copy Link
    • Opswat found two flaws in TP‑Link Tapo C200 cameras: auth bypass (CVE‑2026‑15315) and DoS (CVE‑2026‑15316)
    • Bugs let attackers hijack admin sessions or crash devices; millions of users potentially exposed
    • TP‑Link patched with firmware V5_1.4.6 on Aug 18, 2026; users urged to update immediately

    Security researchers found a pair of vulnerabilities in popular smart cameras, which could allow threat actors to peep into people’s homes and businesses.

    Earlier this week, Opswat disclosed finding two bugs in the TP-Link Tapo C200 smart security camera – an authentication bypass flaw, and a denial-of-service vulnerability. The former is tracked as CVE-2026-15315 and was given a severity score of 8.7/10 (high). Opswat says the bug allows unauthenticated attackers to obtain valid admin sessions without having a password, which would allow them to manage the device and even watch the stream.

    The latter is tracked as CVE-2026-15316. With a severity score of 7.1/10 (high), this bug allows threat actors to send oversized crypted ciphertext values that may trigger exception handling failures and cause the affected device to crash or restart. “Successful exploitation may temporarily disrupt HTTPS management and monitoring functionality, resulting in a denial-of-service (DoS) condition until the service recovers,” according to the NVD.

    Patching the bugs

    The C200 is a mass-market product, advertised as a security camera, a baby monitor, or a pet camera, with motion detection, 1080p video, 2-way audio, night vision, cloud & SD card storage, and integrations with both Alexa and Google Home.

    Opswat disclosed their findings to TP-Link in mid-April this year, which started working on a fix in early July this year. On August 18, 2026, TP-Link released firmware version V5_1.4.6, which addressed both flaws. Users are advised to install the fix as soon as possible.

    The researchers did not discuss if the flaws were being abused in the wild, or to what extent. We do know that TP-Link Tapo cameras are rather popular, with the C200 model being relatively widely sold. According to TP-Link, the Tapo app has more than 13 million users, while the Google Play Store shows 10+ million downloads.

    On Amazon, the C200 specifically is listed as the #1 top rated product in its category, with more than 3,000 purchases this month alone.

    “Camera bugs always get attention because of the “spy factor,” but they usually sound cooler and scarier than they actually are,” said Dahvid Schloss, OSCP, Chief Operating Officer at Suzu Labs. “The main reason not to “worry” about this one is that running this exploit requires local network access, so a threat actor has to be on your Wi-Fi or already own a device that is.

    “If someone’s made it that far into your network, they’re not after the baby monitor. Now, if the camera was port-forwarded to the internet, that’s a bigger design issue and probably should be a concern, but not a common setup for the everyday home user. Either way, I’d still patch the camera, but it’s pretty low on the totem pole of what a cybercriminal wants.”

    “I’m quite curious about the undisclosed vulnerability that reportedly allows full compromise and a foothold to pivot from,” Schloss added. “Based on what was reported, I would guess the exploit would be a command injection or a memory-safety bug in the same management service, chained behind that auth bypass to get code execution as root, where they then dropped a static binary to return a shell on the device whose firmware ships with almost no tooling. That attack chain isn’t uncommon on cheap, older consumer IoT devices where security wasn’t top of mind, but if that’s the case here, seeing it hold up on a modern TP-Link device would be a bit of a blast from the past.

    Computing Computing Security Cyber Security Pro Security
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    myappsplus
    • Website

    Related Posts

    Waiting on your unlocked iPhone 18 Pro? Mint Mobile has an unlimited plan for just $15/mo right now — the perfect pairing

    September 16, 2026

    Google says some Pixel phone owners were hacked in zero-day attacks

    September 16, 2026

    Ring is bringing its Neighbours community feature to the UK next month—here’s how it works, how it’s different from Facebook, and how it uses video doorbells to find lost dogs

    September 16, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    AI, automation, robot dogs ensure on-site nuclear safety

    September 7, 20262 Views

    This tiny AI box could save me from upgrading my perfectly good laptop

    September 6, 20262 Views

    New Target ad delivers look at upcoming deals in one of Nintendo’s ‘largest promotions ever’

    September 13, 20261 Views
    Latest Reviews

    Best Pokémon TCG deals in Best Buy’s 60th Anniversary Sale: Booster packs, sealed collections, and a Pikachu playmat

    myappsplusAugust 19, 2026

    I started using ‘meta-prompting’ in ChatGPT and now I’m getting much better answers — here’s how to do it

    myappsplusAugust 19, 2026

    Spotify’s Running Mode is now available on Android

    myappsplusAugust 19, 2026
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    Best Pokémon TCG deals in Best Buy’s 60th Anniversary Sale: Booster packs, sealed collections, and a Pikachu playmat

    August 19, 20260 Views

    I started using ‘meta-prompting’ in ChatGPT and now I’m getting much better answers — here’s how to do it

    August 19, 20260 Views

    Spotify’s Running Mode is now available on Android

    August 19, 20260 Views
    Our Picks

    Is Phone 4b secretly a CMF device? Carl Pei addresses rebranding rumors

    September 16, 2026

    Samsung starts rolling out Android 17 with One UI 9, confirms initial list of Galaxy devices

    September 16, 2026

    Waiting on your unlocked iPhone 18 Pro? Mint Mobile has an unlimited plan for just $15/mo right now — the perfect pairing

    September 16, 2026

    Subscribe to Updates

    Subscribe to our newsletter and get the latest tech news, app updates, AI trends, smartphone reviews, and exclusive deals delivered straight to your inbox.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Get In Touch
    • Disclaimer
    • Privacy Policy
    • Terms & Conditions
    © 2026 MyAppsPlus. All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.