CVE-2026-78577
Received Received - Intake

Information Disclosure in Tapo C120 and C200 Cameras

Vulnerability report for CVE-2026-78577, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: TPLink

Description

Tapo C120 v1 and C200 V5 contain a vulnerability in the HTTPS onboarding scan function due to missing authentication. After initial setup, an unauthenticated attacker on the same local network can invoke the scan action and retrieve nearby wireless access-point metadata, including SSIDs, BSSIDs, authentication and encryption modes, and signal-strength information. Successful exploitation may disclose information about the wireless environment surrounding the camera, allowing an attacker to learn elements of the local wireless topology.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
tapo c120 1
tapo c200 5

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Tapo C120 v1 and C200 V5 devices. It involves a missing authentication check in the HTTPS onboarding scan function. An unauthenticated attacker on the same local network can trigger the scan action and retrieve metadata about nearby wireless access points, including SSIDs, BSSIDs, encryption modes, and signal strength.

Detection Guidance

This vulnerability can be detected by checking for unauthorized HTTPS scan requests on the local network targeting Tapo C120 or C200 devices. Monitor network traffic for HTTPS POST requests to the scan endpoint without prior authentication. Use tools like Wireshark to capture and inspect traffic for SSID, BSSID, or signal-strength metadata being transmitted.

Impact Analysis

An attacker could exploit this to gather information about your local wireless network environment. This includes learning details about nearby access points, which might help in planning further attacks or mapping your network topology without your knowledge.

Compliance Impact

This vulnerability may expose wireless network metadata (SSIDs, encryption modes) which could indirectly aid in unauthorized network access. For GDPR, this could relate to risks of unauthorized data collection or network intrusion. For HIPAA, it might affect safeguards for protected health information if network access is compromised.

Mitigation Strategies

Disable the HTTPS onboarding scan function on affected Tapo C120 v1 and C200 V5 devices to prevent unauthenticated access to wireless network metadata.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-78577. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart