๐Ÿ” CVE Alert

CVE-2026-15315

UNKNOWN 0.0

Unauthenticated Administrative Authentication Bypass via device_confirm Replay in TP-Link Tapo C200

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Tapo C200 v5 contains an improper authentication vulnerability within the login authentication verification module. An attacker on the local network can exploit weaknesses in challenge parameter validation to bypass normal authentication controls and obtain administrative session tokens. Successful exploitation may allow an attacker to subsequently execute privileged management actions, enable unauthorized administrative access and temporary disruption of device services, resulting in a denial-of-service (DoS) condition.

CWE CWE-287
Vendor tp-link systems inc.
Product tapo c200 v5
Published Aug 18, 2026
Stay Ahead of the Next One

Get instant alerts for tp-link systems inc. tapo c200 v5

Be the first to know when new unknown vulnerabilities affecting tp-link systems inc. tapo c200 v5 are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

TP-Link Systems Inc. / Tapo C200 v5
0 < V5_1.4.6 Build 260709 Rel.27675n

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
tp-link.com: https://www.tp-link.com/us/support/download/tapo-c200/v5/ tp-link.com: https://www.tp-link.com/en/support/download/tapo-c200/v5/ tp-link.com: https://www.tp-link.com/us/support/faq/5248/

Credits

Thai Do (Lio) and Khoi Tran (KayTii) from OPSWAT