Close Menu
MyAppsPlus

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Qualcomm announces Snapdragon Sound Elite Gen 2 for AI ‘hearables,’ even ones with cameras

    September 23, 2026

    Modal Motors is trying to cut China out of electric motors entirely

    September 23, 2026

    Luriax cases wrap iPhone 18 Pro in suede-like Lamborghini Alcantara [Exclusive deal]

    September 23, 2026
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram
    MyAppsPlusMyAppsPlus
    Wednesday, September 23
    • Home
    • Breaking Tech
    • Apps & Software
    • AI & Automation
    • Android
    • iPhone & iOS
    • More
      • Reviews
      • How-To Guides
      • Deals & Discounts
      • Shop
    MyAppsPlus
    Home»Reviews»These popular TP-Link home security cameras could be hacked to spy on you while you sleep, experts warn
    Reviews

    These popular TP-Link home security cameras could be hacked to spy on you while you sleep, experts warn

    myappsplusBy myappsplusSeptember 23, 2026003 Mins Read
    Share Facebook Twitter Pinterest Copy Link LinkedIn Tumblr Email Telegram WhatsApp
    Follow Us
    Google News Flipboard
    These popular TP-Link home security cameras could be hacked to spy on you while you sleep, experts warn
    Share
    Facebook Twitter LinkedIn Pinterest Email Copy Link
    • Cybersecurity company OPSWAT found a login bypass and a crash bug in TP-Link’s Tapo C200 cameras
    • TP-Link has extended that to include its C120 offering too
    • Anyone on the same network could get admin access, live video, and recordings without requiring the owner’s credentials

    Security researchers at OPSWAT have detailed two high-severity flaws in TP-Link’s Tapo C200, a pan-and-tilt indoor camera listed on Amazon for $26.99 and sold as a baby monitor and pet camera.

    The more serious issue is that someone on the same network can log in as the camera’s administrator without the password, accessing the live feed and stored recordings.

    At least one other bug, which OPSWAT rates as critical in the same disclosure but does not detail, has not been published.

    A localized login that requires no authentication

    The TP-Link Tapo C200, as we noted in previous coverage of the incident, isn’t just another security camera that happens to be vulnerable; it is one of the most popular models on the market, clocking in at over 3,000 sales on Amazon alone.

    The Tapo C120, in its current iteration, sells over 5,000 units monthly, even as the advisory notes that its V1 hardware version is currently compromised until users update the firmware on their devices.

    Both SKUs have received firmware updates that patch the vulnerabilities (CVE-2026-15315 & CVE-2026-15316), which are assigned ‘high’ scores of 8.7 and 7.1, respectively. However, according to TP-Link, CVE-2026-15316 does not affect the C120 camera.

    However, the former vulnerability is the more pressing of the two and is particularly problematic for users because of how the C120 and C200 cameras function

    Both run a local management interface over HTTPS and use a challenge-response login designed to prove a client knows the owner’s password. Khoi Tran, a graduate fellow at OPSWAT, and his mentor, Thai Do of the company’s Unit 515 team, found a second verification path in which, under certain conditions, a value the camera hands out during login can be sent back and accepted as a valid authentication response.

    The result is an administrator session after a small number of requests, with no password, no existing session, and no requirements for the new ‘owner’. As a result, access includes live video, stored footage, and configuration changes.

    OPSWAT’s researchers pointed out that a C200 used as a baby monitor would expose “live video, night vision, crying detection and two-way audio.”

    The second flaw, CVE-2026-15316, affects only the C200 and sits in its Wi-Fi onboarding code. Sending the camera an oversized chunk of encrypted Wi-Fi credential data can crash its HTTPS service or restart the device outright, cutting the owner off from management and monitoring until it recovers.

    The attacks are somewhat limited in scope: users aiming to exploit such vulnerabilities would need to be on the same Wi-Fi network, or within a certain trusted ecosystem, to begin with.

    For now, users upgrading to TP-Link’s newest firmware, issued for both models, rectifies both issues, but there might already be another security patch in the works: OPSWAT also found “a critical vulnerability that could allow an attacker to fully compromise the camera,” which could then serve as a foothold inside the network.

    It is currently holding off on publishing any details about the vulnerability as it waits for TP-Link to issue a patch that rectifies the situation. Neither OPSWAT nor TP-Link, however, has provided a timeline for when the patch will be available to end users.

    Computing Computing Security Cyber Security Home Home Security Pro Security Smart Home
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    myappsplus
    • Website

    Related Posts

    Interpol uses AI to identify 126 terrorists by analyzing over 100,000 images with new facial recognition tools

    September 23, 2026

    It’s Nintendo’s 135th birthday, but you get the presents: Grab these Switch 2 games and Lego sets

    September 23, 2026

    Prepare for power outages with this discounted Jackery HomePower 3600 Plus power station

    September 23, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Top 10 Best React Native App Development Companies in 2026

    September 12, 20263 Views

    This tiny AI box could save me from upgrading my perfectly good laptop

    September 6, 20263 Views

    New Target ad delivers look at upcoming deals in one of Nintendo’s ‘largest promotions ever’

    September 13, 20262 Views
    Latest Reviews

    $500 off MacBook, AirPads Pro 3, Max 2 $120 off, AirTag 2, more from $13

    myappsplusAugust 21, 2026

    The $225 Pebble Time 2 is a refreshingly fun smartwatch

    myappsplusAugust 21, 2026

    No driver, no problem — devs use Claude AI to craft native macOS tool for an ‘obscure’ Windows-only printer

    myappsplusAugust 21, 2026
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    $500 off MacBook, AirPads Pro 3, Max 2 $120 off, AirTag 2, more from $13

    August 21, 20260 Views

    The $225 Pebble Time 2 is a refreshingly fun smartwatch

    August 21, 20260 Views

    No driver, no problem — devs use Claude AI to craft native macOS tool for an ‘obscure’ Windows-only printer

    August 21, 20260 Views
    Our Picks

    Qualcomm announces Snapdragon Sound Elite Gen 2 for AI ‘hearables,’ even ones with cameras

    September 23, 2026

    Modal Motors is trying to cut China out of electric motors entirely

    September 23, 2026

    Luriax cases wrap iPhone 18 Pro in suede-like Lamborghini Alcantara [Exclusive deal]

    September 23, 2026

    Subscribe to Updates

    Subscribe to our newsletter and get the latest tech news, app updates, AI trends, smartphone reviews, and exclusive deals delivered straight to your inbox.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Get In Touch
    • Disclaimer
    • Privacy Policy
    • Terms & Conditions
    © 2026 MyAppsPlus. All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.