HIGH · 8.8

CVE-2026-15315

Tapo C120 v1 and C200 v5 contain an improper authentication vulnerability within the login authentication verification module. An attacker on the local network can exploit weaknesses in challenge para...

Vulnerability Description

Tapo C120 v1 and C200 v5 contain an improper authentication vulnerability within the login authentication verification module. An attacker on the local network can exploit weaknesses in challenge parameter validation to bypass normal authentication controls and obtain administrative session tokens. Successful exploitation may allow an attacker to subsequently execute privileged management actions, enable unauthorized administrative access and temporary disruption of device services, resulting in a denial-of-service (DoS) condition.

CVSS Score

8.8

HIGH

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
Tp-LinkTapo C120 Firmware< 1.9.3
Tp-LinkTapo C120-
Tp-LinkTapo C200 Firmware< 1.4.6
Tp-LinkTapo C2005.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-15315?

CVE-2026-15315 is a vulnerability with a CVSS score of 8.8 (HIGH). Tapo C120 v1 and C200 v5 contain an improper authentication vulnerability within the login authentication verification module. An attacker on the local network can exploit weaknesses in challenge para...

How severe is CVE-2026-15315?

CVE-2026-15315 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2026-15315?

Check the references section above for vendor advisories and patch information. Affected products include: Tp-Link Tapo C120 Firmware, Tp-Link Tapo C120, Tp-Link Tapo C200 Firmware, Tp-Link Tapo C200.