CVE-2026-15315
Unauthenticated Administrative Authentication Bypass via device_confirm Replay in TP-Link Tapo C200
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Tapo C200 v5 contains an improper authentication vulnerability within the login authentication verification module. An attacker on the local network can exploit weaknesses in challenge parameter validation to bypass normal authentication controls and obtain administrative session tokens. Successful exploitation may allow an attacker to subsequently execute privileged management actions, enable unauthorized administrative access and temporary disruption of device services, resulting in a denial-of-service (DoS) condition.
| CWE | CWE-287 |
| Vendor | tp-link systems inc. |
| Product | tapo c200 v5 |
| Published | Aug 18, 2026 |
Stay Ahead of the Next One
Get instant alerts for tp-link systems inc. tapo c200 v5
Be the first to know when new unknown vulnerabilities affecting tp-link systems inc. tapo c200 v5 are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
TP-Link Systems Inc. / Tapo C200 v5
0 < V5_1.4.6 Build 260709 Rel.27675n
References
Credits
Thai Do (Lio) and Khoi Tran (KayTii) from OPSWAT