Vulnerability record · CVE-2026-15315 · published 18 August 2026
CVE-2026-15315: Tp-link tapo c120 firmware improper authentication vulnerability
Tp Link · Tapo C120 Firmware
Tapo C120 v1 and C200 v5 contain an improper authentication vulnerability within the login authentication verification module. An attacker on the local network can exploit weaknesses in challenge parameter validation to bypass normal authentication controls and obtain administrative session tokens. Successful exploitation may allow an attacker to subsequently execute privileged management actions, enable unauthorized administrative access and temporary disruption of device services, resulting in a denial-of-service (DoS) condition.
Description
Tapo C120 v1 and C200 v5 contain an improper authentication vulnerability within the login authentication verification module. An attacker on the local network can exploit weaknesses in challenge parameter validation to bypass normal authentication controls and obtain administrative session tokens. Successful exploitation may allow an attacker to subsequently execute privileged management actions, enable unauthorized administrative access and temporary disruption of device services, resulting in a denial-of-service (DoS) condition.
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.tp-link.com/en/support/download/tapo-c120/v1.26/#Firmware-Release-Notes | Release NotesProduct |
| https://www.tp-link.com/en/support/download/tapo-c200/v5/ | ProductRelease Notes |
| https://www.tp-link.com/us/support/download/tapo-c120/v1.26/#Firmware-Release-Notes | Release NotesProduct |
| https://www.tp-link.com/us/support/download/tapo-c200/v5/ | ProductRelease Notes |
| https://www.tp-link.com/us/support/faq/5248/ | Vendor AdvisoryPatch |
Track CVE-2026-15315 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2026-15315), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.