TP-Link Tapo C200 Security Flaw Could Let Hackers Take Control of Camera, Users Urged to Install Latest Firmware

TP-Link Tapo C200 has critical security flaws that could enable camera takeover and network attacks. Update firmware to protect your device.

TP-Link Tapo C200 Security Flaw Could Let Hackers Take Control of Camera, Users Urged to Install Latest Firmware

Security researchers have found multiple TP-Link Tapo C200 security vulnerabilities, including a critical flaw that could allow attackers to take full control of the camera and use it to enter other devices on the same network. The findings were reported by cybersecurity company OPSWAT, which examined the camera’s firmware and local communication systems. The TP-Link Tapo C200 is an affordable indoor security camera commonly used as a baby monitor, pet monitor or home surveillance camera. Users can watch live camera footage through the Tapo mobile app.

OPSWAT identified three software vulnerabilities in the camera. According to the researchers, the most serious flaw is still under investigation. If successfully exploited, it could allow an attacker to fully compromise the camera and potentially use it as a foothold to target other devices and systems connected to the same network.

One of the other vulnerabilities, tracked as CVE-2026-15315, could allow an attacker with access to the local network to get a valid administrator session without knowing the camera password. This could give the attacker access to important camera settings and other administrator functions. Another flaw, CVE-2026-15316, could cause the Tapo C200 to crash or restart. An attacker could send specially created data to the camera, causing errors that may take the device offline. This vulnerability also requires local network access.

The update for users is that TP-Link has released firmware updates to address the reported vulnerabilities. The company has also updated the firmware for the Tapo C120, which is affected by the same issues. TP-Link stated it takes product security and customer privacy seriously and investigated the vulnerabilities after receiving the researchers' report. The company confirmed that the reported issues affecting the Tapo C200 V5 have been fixed. Users can install the latest firmware through the Tapo mobile app. TP-Link recommends keeping Tapo cameras updated with the latest available firmware to ensure security fixes are applied.

The findings highlight why smart home security cameras should be regularly updated. Users should check their Tapo camera firmware, use strong passwords and keep their home network protected to reduce the risk of unauthorized access.

This article is based on information from PCmag