Security researchers have disclosed two zero-day vulnerabilities in TP-Link security cameras widely deployed in homes and small offices, one of which could let attackers conduct unauthorized surveillance. OPSWAT released details of the bugs affecting the TP-Link Tapo C200 camera, a device frequently used for monitoring babies and pets, residential security, and small business protection. The Chinese manufacturer patched both flaws in firmware version V5_1.4.6, which became available on August 18.
The first vulnerability, CVE-2026-15315, is an authentication bypass that exploits replay techniques to grant network-based attackers administrative control without requiring password knowledge or recovery. The second flaw, CVE-2026-15316, creates a denial-of-service condition in the camera's setup process. OPSWAT explained that CVE-2026-15315 allows unauthorized users to execute privileged management operations, alter device settings, and access functions normally restricted to authorized administrators. This administrative access can expose privacy-critical features including real-time video feeds and archived footage, enabling illicit monitoring of content captured by the compromised device. CVE-2026-15316 stems from inadequate validation of encrypted credential information before it enters cryptographic and configuration-handling systems. Network-connected attackers without authentication can transmit excessively large encrypted credential values, causing the camera's HTTPS service to fail when the corrupted data reaches the susceptible processing pathway.
Dahvid Schloss, COO at Suzu Labs, noted that the high-severity authentication flaw poses less risk than initial appearances suggest because exploitation requires the attacker to already be present on the same network as the targeted camera. "If someone's made it that far into your network, they're not after the baby monitor," he stated. OPSWAT is currently collaborating with TP-Link on an additional zero-day vulnerability it discovered, which the research firm rates as critical severity. The undisclosed flaw could enable complete device compromise and allow attackers to establish a persistent presence within the network using the camera as an entry point.
The critical third vulnerability will remain under wraps until TP-Link develops and releases a fix, following responsible disclosure practices. Schloss speculated the exploit likely involves command injection or memory-safety defects in the management service, chained with the authentication bypass to achieve root-level code execution and deploy static binaries that return shell access on devices whose firmware ships with minimal tooling. He noted that while such attack chains are common on inexpensive, older consumer IoT products where security wasn't prioritized, seeing this pattern persist on modern TP-Link hardware would represent a troubling throwback. The broader risk extends beyond individual cameras—once attackers gain a foothold through compromised IoT devices, they can pivot to more valuable network targets, turning seemingly low-stakes home security products into gateways for lateral movement. For organizations and households alike, the immediate action is clear: update affected Tapo C200 cameras to firmware V5_1.4.6 or later, verify network segmentation to isolate IoT devices, and monitor for the forthcoming patch addressing the critical third flaw. Device manufacturers face mounting pressure to elevate security standards across consumer-grade products, particularly as remote work blurs the line between home and enterprise networks. The disclosure serves as a reminder that convenience-focused devices can become liability-focused vulnerabilities when left unpatched or improperly configured.

