๐Ÿ” CVE Alert

CVE-2026-15315

UNKNOWN 0.0

Unauthenticated Administrative Authentication Bypass via device_confirm Replay in TP-Link Tapo C120 and C200

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Tapo C120 v1 and C200 v5 contain an improper authentication vulnerability within the login authentication verification module. An attacker on the local network can exploit weaknesses in challenge parameter validation to bypass normal authentication controls and obtain administrative session tokens. Successful exploitation may allow an attacker to subsequently execute privileged management actions, enable unauthorized administrative access and temporary disruption of device services, resulting in a denial-of-service (DoS) condition.

CWE CWE-287
Vendor tp-link systems inc.
Product tapo c200 v5
Published Aug 18, 2026
Last Updated Aug 27, 2026
Stay Ahead of the Next One

Get instant alerts for tp-link systems inc. tapo c200 v5

Be the first to know when new unknown vulnerabilities affecting tp-link systems inc. tapo c200 v5 are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

TP-Link Systems Inc. / Tapo C200 v5
0 < V5_1.4.6 Build 260709 Rel.27675n
TP-Link Systems Inc / Tapo C120 v1
0 < 1.9.3 Build 260521

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
tp-link.com: https://www.tp-link.com/us/support/download/tapo-c200/v5/ tp-link.com: https://www.tp-link.com/en/support/download/tapo-c200/v5/ tp-link.com: https://www.tp-link.com/us/support/faq/5248/ tp-link.com: https://www.tp-link.com/us/support/download/tapo-c120/v1.26/#Firmware-Release-Notes tp-link.com: https://www.tp-link.com/en/support/download/tapo-c120/v1.26/#Firmware-Release-Notes

Credits

Thai Do (Lio) and Khoi Tran (KayTii) from OPSWAT Max Aitel