CVE-2026-15315

Tapo C120 v1 and C200 v5 contain an improper authentication vulnerability within the login authentication verification module. An attacker on the local network can exploit weaknesses in challenge parameter validation to bypass normal authentication controls and obtain administrative session tokens. Successful exploitation may allow an attacker to subsequently execute privileged management actions, enable unauthorized administrative access and temporary disruption of device services, resulting in a denial-of-service (DoS) condition.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:tp-link:tapo_c120_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:tapo_c120:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:tp-link:tapo_c200_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:tapo_c200:5.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-08-18 22:16

Updated : 2026-09-04 17:39


NVD link : CVE-2026-15315

Mitre link : CVE-2026-15315

CVE.ORG link : CVE-2026-15315


JSON object : View

Products Affected

tp-link

  • tapo_c120_firmware
  • tapo_c120
  • tapo_c200
  • tapo_c200_firmware
CWE
CWE-287

Improper Authentication