TP-Link Tapo C200 zero-day auth bypass and DoS (multiple vulnerabilities)
VulnerabilityFirst reported
Last updated
Happening score
H score
41
Summary
Hide ▲
Show ▼
Two zero-day vulnerabilities in the TP-Link Tapo C200 camera could let a network-access attacker gain administrator access, view live video and recordings, or trigger a device crash, and TP-Link has already fixed them in firmware V5_1.4.6.
Related Happenings
Mirai-based CVE-2025-29635 D-Link DIR-823X botnet-enlistment campaign
Campaign
H score38
First: 22.04.2026 23:04
Last: 22.04.2026 23:04
Sources 1
About this happening:
The Mirai-based malware campaign is actively exploiting CVE-2025-29635 against D-Link DIR-823X routers, turning vulnerable devices into botnet nodes. The activity matt...
Mirai-based CVE-2025-29635 D-Link DIR-823X botnet-enlistment campaign
Campaign
H score38
First: 22.04.2026 23:04
Last: 22.04.2026 23:04
Sources 1
About this happening: The Mirai-based malware campaign is actively exploiting CVE-2025-29635 against D-Link DIR-823X routers, turning vulnerable devices into botnet nodes. The activity matt...
Timeline
-
16.09.2026 13:00 2 articles · 2h ago
TP-Link Tapo C200 zero-day auth bypass and DoS (multiple vulnerabilities)
Initial DisclosureResearchers disclosed CVE-2026-15315 and CVE-2026-15316 for the TP-Link Tapo C200, showing that a network-access attacker could gain admin control or crash the camera's web service. TP-Link had already shipped firmware V5_1.4.6 as the remediation path.
Show sources
- Zero-Day Flaw in TP-Link Cameras Enables Eavesdropping — www.infosecurity-magazine.com — 16.09.2026 13:00
- Zero-Day Flaw in TP-Link Cameras Enables Eavesdropping — www.infosecurity-magazine.com — 16.09.2026 13:00