CVE-2026-15315
Analyzed Analyzed - Analysis Complete

Authentication Bypass in Tapo C200 v5

Vulnerability report for CVE-2026-15315, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-18

Last updated on: 2026-09-04

Assigner: TPLink

Description

Tapo C120 v1 and C200 v5 contain an improper authentication vulnerability within the login authentication verification module. An attacker on the local network can exploit weaknesses in challenge parameter validation to bypass normal authentication controls and obtain administrative session tokens. Successful exploitation may allow an attacker to subsequently execute privileged management actions, enable unauthorized administrative access and temporary disruption of device services, resulting in a denial-of-service (DoS) condition.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-18
Last Modified
2026-09-04
Generated
2026-09-08
AI Q&A
2026-08-19
EPSS Evaluated
2026-09-07
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
tp-link tapo_c120_firmware to 1.9.3 (exc)
tp-link tapo_c200_firmware to 1.4.6 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-287 When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an improper authentication issue in the Tapo C200 v5 device. It allows an attacker on the local network to bypass login authentication by exploiting weaknesses in the validation of the challenge parameter. This lets them obtain administrative session tokens without proper credentials.

Detection Guidance

Detecting this vulnerability requires network monitoring for unauthorized administrative access attempts or unusual challenge parameter handling. Check Tapo C200 device logs for repeated failed login attempts or unexpected session token generation. Use network scanning tools like nmap to identify vulnerable devices on your local network.

Impact Analysis

An attacker could gain unauthorized administrative access to the device, execute privileged management actions, or disrupt services causing a temporary denial-of-service condition. This compromises the device's security and functionality.

Compliance Impact

This vulnerability allows unauthorized administrative access and potential denial-of-service conditions, which could lead to unauthorized data access or processing. Such breaches may violate GDPR's data protection requirements or HIPAA's safeguards for protected health information if the device handles such data.

Mitigation Strategies

Immediately isolate affected Tapo C200 devices from the local network if possible. Disable remote administration features if enabled. Update the device firmware to the latest version if a patch is available. Monitor device logs for suspicious activity and consider replacing the device if no patch is issued.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-15315. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart