Severe TP-Link Tapo camera flaw lets hackers watch live feed from your home
They could be peeping inside your house even at night.

Image by Cybernews
- Researchers found three flaws in TP-Link Tapo C200 cameras, including two disclosed high-severity vulnerabilities.
- One flaw could let attackers on the same network gain admin access without the owner’s password.
- Researchers say another undisclosed flaw could let attackers take over a camera and target other network devices.
- TP-Link has issued updated firmware, and users should update cameras and avoid exposing them online.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
Hackers could hijack popular TP-Link home security cameras to spy on people, watch live video inside the home, and eavesdrop or speak through devices, researchers have discovered.
In a potentially more serious attack, a compromised camera could be used as a foothold to target other devices on the same network, according to security researchers at critical infrastructure security firm OPSWAT.
The researchers found serious vulnerabilities in the TP-Link Tapo C200, a widely sold camera used for home security, monitoring pets and watching over babies, as well as in some business environments.
Tapo flaw allows admin access
One of the flaws – tracked as CVE-2026-15315 – is rated “high severity” and could allow an attacker with network access to the camera to bypass its login system and gain admin privileges without knowing the owner’s password.
According to OPSWAT, the C200 uses a challenge-response system designed to prove that someone attempting to log in knows the camera’s password.
However, researchers discovered that information previously sent to the camera could be replayed and incorrectly accepted as authentication.
Once an attacker has a network path to the camera, exploitation requires “only a handful of malicious requests” and could take just “a few minutes”.
That could potentially give an intruder access to live video and stored recordings and allow them to change camera settings or use other administrator-only functions.
OPSWAT adds in its blog that, if the devices are being used as a monitor, the implications are particularly concerning.
If the C200 camera is used as a baby monitor, an attacker could access privacy-sensitive functionality such as live video, night vision, crying detection and two-way audio.– OPSWAT researchers warn.
Network takeover flaw
OPSWAT reported that another flaw found during investigation could let an attacker take full control of the camera and use it to attack other devices on the same network.
However, details of this vulnerability have not been publicly released while the security firm works with TP-Link to confirm and fix it.
In its report, the security firm added: “Further technical details will be shared once appropriate fixes are available and the coordinated disclosure process is complete.”
Crash flaw discovered
Another authenticated high-severity vulnerability, tracked as CVE-2026-15316, was also found in configuration data processed during camera setup.
An attacker on the network can deliberately send large amounts of traffic to the device, causing the camera’s management service to crash, knocking it offline and locking the legitimate owner out until it recovers.
All three flaws were discovered in a lab by graduate researcher Khoi Tran, under the mentorship of Thai Do, while examining the camera’s firmware as part of an OPSWAT graduate programme.
The vendor released updated firmware and a security advisory on August 18th.
Tapo C200 users urged to update firmware
All Tapo C200 cameras running firmware released before that update are affected by the two disclosed vulnerabilities.
Users are being urged to install the latest firmware immediately, avoid exposing cameras directly to the internet, and secure their WiFi networks.
Businesses are advised to isolate camera networks and restrict access to authorised devices and users.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
The findings are not the first security issues discovered in TP-Link products.
In March, critical vulnerabilities were found in several TP-Link Archer NX routers that could allow attackers to bypass authentication and perform privileged operations.