logo

TP-Link Cameras 0-Day Vulnerabilities Allow Attackers to Spy on Users

ID: f6922236-d7ae-50c2-b325-58dc00c382b3

STIX ID: report--f6922236-d7ae-50c2-b325-58dc00c382b3

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2026-09-16

Date Updated: 2026-09-16

Author: Abinaya

...
...

TP-Link Tapo C200 cameras were found to contain two zero-day flaws—CVE-2026-15315 (an authentication-bypass in the local HTTPS management interface that can allow attacker-created administrative sessions via replayed values) and CVE-2026-15316 (an unauthenticated denial-of-service in Wi‑Fi onboarding caused by improper validation of encrypted credential size). Discovered by OPSWAT researchers and disclosed to TP-Link, both issues were fixed in firmware V5_1.4.6 (released 2026-08-18); users are advised to update firmware, restrict management interfaces to trusted networks, and segment IoT devices.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.