Find notable cyber news and cases, enriched with sources, timelines, and signals.

TP-Link Tapo C200 zero-day auth bypass and DoS (multiple vulnerabilities)

Vulnerability
First reported
Last updated
Happening score
H score 41
1 unique sources, 1 articles

Summary

Hide ▲

Two zero-day vulnerabilities in the TP-Link Tapo C200 camera could let a network-access attacker gain administrator access, view live video and recordings, or trigger a device crash, and TP-Link has already fixed them in firmware V5_1.4.6.

Related Happenings

Mirai-based CVE-2025-29635 D-Link DIR-823X botnet-enlistment campaign

Campaign
H score38 First: 22.04.2026 23:04 Last: 22.04.2026 23:04 Sources 1

About this happening: The Mirai-based malware campaign is actively exploiting CVE-2025-29635 against D-Link DIR-823X routers, turning vulnerable devices into botnet nodes. The activity matt...

Timeline

  1. 16.09.2026 13:00 2 articles · 2h ago

    TP-Link Tapo C200 zero-day auth bypass and DoS (multiple vulnerabilities)

    Initial Disclosure

    Researchers disclosed CVE-2026-15315 and CVE-2026-15316 for the TP-Link Tapo C200, showing that a network-access attacker could gain admin control or crash the camera's web service. TP-Link had already shipped firmware V5_1.4.6 as the remediation path.

    Show sources