CVE-2026-78578
Received Received - Intake

Authentication Bypass in Tapo C120 and C200 Cameras

Vulnerability report for CVE-2026-78578, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: TPLink

Description

Tapo C120 v1 and C200 v5 do not enforce authentication for do method HTTPS onboarding connect actions after initial setup.Β  An unauthenticated adjacent attacker can submit unauthorized wireless configuration parameters, causing the camera to attempt connection to a different network. Successful exploitation disconnects the camera from its intended wireless network, making it unreachable on its management address, resulting in a denial-of-service condition.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
tapo c120 1
tapo c200 5

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Tapo C120 v1 and C200 v5 cameras. After initial setup, the cameras do not enforce authentication for HTTPS onboarding connect actions. An unauthenticated attacker within proximity can send unauthorized wireless configuration parameters, forcing the camera to connect to a different network. This disconnects the camera from its intended network, making it unreachable for management and causing a denial-of-service condition.

Detection Guidance

This vulnerability involves unauthenticated HTTPS onboarding actions in Tapo C120 v1 and C200 v5 cameras. To detect it, monitor network traffic for unauthorized wireless configuration submissions to the camera's management interface. Check for unexpected disconnections from the intended Wi-Fi network.

Impact Analysis

An attacker could exploit this to take control of your camera, disconnect it from your network, and prevent you from accessing or managing it. This could lead to loss of surveillance, privacy breaches, or disruption of security monitoring.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by allowing unauthorized network access to surveillance cameras. Unauthenticated attackers could disconnect devices from their intended networks, disrupting monitoring and recording capabilities. This may violate data integrity and availability requirements under these regulations.

Mitigation Strategies

Ensure the Tapo C120 v1 and C200 v5 cameras are updated to the latest firmware that enforces authentication for HTTPS onboarding connect actions. Disable remote or adjacent network access to the camera's management interface if not required.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-78578. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart