CVE-2026-102369
Received Received - Intake

Command Injection in Tapo C120 and C200 Cameras

Vulnerability report for CVE-2026-102369, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: TPLink

Description

Tapo C120 v1 and C200 V5 do not adequately protect login challenge data or sanitize attacker-controlled input processed by the MacTool handler. An unauthenticated attacker on the same local network can replay login challenge data to obtain an administrative session, enable a privileged service that becomes accessible after a reboot, and submit crafted input to execute arbitrary commands within the device management process. Successful exploitation may allow arbitrary command execution on the camera and compromise the confidentiality, integrity, and availability of the affected device. Exploitation requires access from the same local network, replay of the login challenge data, activation of the privileged service, and a device reboot.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
tp-link tapo_c120 v1.1.9.4
tp-link tapo_c200 v5.1.4.6
tp-link tapo_c120 to 1.26 (inc)
tp-link tapo_c200 to 1.26 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-287 When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Tapo C120 v1 and C200 V5 cameras. It involves insufficient protection of login challenge data and inadequate input sanitization in the MacTool handler. An unauthenticated attacker on the same local network can replay login challenge data to gain an administrative session, enable a privileged service after a reboot, and execute arbitrary commands within the device's management process.

Detection Guidance

Detection requires checking if the Tapo C120 v1 or C200 v5 devices are running outdated firmware versions. Verify the current firmware version via the device's web interface or mobile app. If the version is below V1_1.9.4 Build 260813 Rel.79754n for C120 v1 or V5_1.4.6 Build 260709 Rel.27675n for C200 v5, the device is vulnerable.

Impact Analysis

Successful exploitation may allow arbitrary command execution on the camera, compromising its confidentiality, integrity, and availability. Attackers could gain full control over the device, potentially accessing sensitive data or using it as a foothold in a network.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by compromising the confidentiality, integrity, and availability of the affected Tapo cameras. Unauthorized access to camera feeds or data could lead to unauthorized data processing or disclosure, violating GDPR principles. For HIPAA, if the cameras are used in healthcare settings, the breach could expose protected health information, leading to compliance violations.

Mitigation Strategies

Immediately update the firmware of affected Tapo C120 v1 and C200 v5 devices to the latest versions: V1_1.9.4 Build 260813 Rel.79754n for C120 v1 and V5_1.4.6 Build 260709 Rel.27675n for C200 v5. Ensure the devices are isolated from untrusted networks and restrict local network access to trusted devices only.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102369. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart