Skip to main content
IoT SecurityVulnerability Patch· 3 min read· in Technology

TP-Link Patches Authentication Bypass Flaw in Tapo C200 Smart Cameras

Security researchers have disclosed a high-severity vulnerability in TP-Link's popular Tapo C200 indoor camera that allowed attackers to view live video feeds without a password. TP-Link has released a firmware update to close the loophole.

By Wei Zhang

Cybersecurity Researchers 50%Consumer Tech Advocates 50%
Cybersecurity Researchers
Focuses on the technical severity of the flaw and the structural failure of shipping devices with vulnerable local web servers.
Consumer Tech Advocates
Emphasizes the practical impact on users, the limitations of the threat model, and the immediate mitigation steps required.

Perspectives this story doesn't cover

  • TP-Link Engineering Team
  • Smart Home Device Regulators

Why this matters

Millions of households use inexpensive indoor cameras as baby monitors or security devices, relying on password protection to keep the footage private. This flaw demonstrates how easily network-connected hardware can expose the exact spaces it was purchased to secure, making immediate firmware updates critical for owners.

A network-connected security camera only functions as a security device if its video feed remains strictly inaccessible to anyone lacking the correct credentials. That fundamental constraint failed in one of the market's most popular budget indoor cameras, the TP-Link Tapo C200, after researchers discovered a high-severity authentication bypass vulnerability.[1][3]

Researchers at the cybersecurity firm HackYourMom disclosed the zero-day flaw on September 16, 2026, revealing that an attacker could gain unauthenticated administrative access to the hardware. By exploiting a weakness in how the camera handles session tokens, a malicious actor could bypass the login screen entirely and access the 1080p video stream.[1][2]

Once inside, the intruder would possess the exact same privileges as the device owner, including viewing the live video stream, rotating the lens, and disabling the device entirely. While the initial technical disclosures from researchers do not include direct statements from TP-Link executives, the consensus across the security community emphasizes the severity of the unauthenticated access.[2][3]

Users must manually initiate the firmware update through the Tapo mobile application to secure their devices.

The Tapo C200 is a ubiquitous piece of smart home hardware, frequently retailing for under $30 and widely deployed as a baby monitor or pet camera. It features a 360-degree horizontal pan and a 114-degree vertical tilt, mechanical movements that an attacker exploiting this flaw could trigger remotely to survey a room, alongside accessing up to 128 GB of local microSD storage.[3][4]

The Tapo C200 is a ubiquitous piece of smart home hardware, frequently retailing for under $30 and widely deployed as a baby monitor or pet camera.

The technical mechanism centers on the camera's local web server, which failed to properly validate the length and structure of authentication requests. According to Rewterz, the vulnerability carries a high-severity designation because it requires zero user interaction and bypasses the primary security boundary protecting the device's 2.4 GHz Wi-Fi connection.[5]

Despite the severity of the access granted, the actual threat model is narrower than some initial alerts suggested. The exploit requires the attacker to already have access to the same local network as the camera, or for the camera to be explicitly exposed to the public internet via port forwarding. It is not a remote-code execution flaw that allows anyone on the internet to arbitrarily scan and compromise devices behind a standard home router.[3][4]

The vulnerability requires the attacker to be on the same local network as the camera, limiting the risk of remote internet-wide exploitation.

TP-Link has acknowledged the vulnerability and pushed a firmware update to address the authentication loophole, though the company did not provide direct public commentary or executive statements in the initial disclosure reports. Owners are required to open the Tapo mobile application and navigate to the device settings to initiate the download, as the cameras do not always apply critical security patches automatically by default.[1][4]

The incident highlights a persistent structural issue in the smart home market: the rush to produce highly capable, inexpensive hardware often leaves software validation trailing behind. Until manufacturers mandate automatic, silent security updates for all internet-of-things devices, the burden of maintaining the digital perimeter remains entirely on the consumer's willingness to check an app for updates.[2][5]

Viewpoints in depth

Cybersecurity Researchers

Focuses on the technical severity of the flaw and the structural failure of shipping devices with vulnerable local web servers.

Security analysts view the Tapo C200 vulnerability as a textbook example of the internet-of-things security debt. By failing to properly sanitize and validate session tokens on the local web server, the device effectively trusted any local network traffic by default. Researchers argue that this design pattern is fundamentally flawed, as local networks are increasingly hostile environments shared with dozens of other smart devices, any of which could be compromised and used as a pivot point.

Consumer Tech Advocates

Emphasizes the practical impact on users, the limitations of the threat model, and the immediate mitigation steps required.

While acknowledging the severity of the flaw, consumer technology outlets emphasize that the sky is not falling for the average user. Because the vulnerability is not a remote-code execution flaw that can be exploited from across the globe, the immediate risk is limited to targeted local attacks or users who have improperly configured their home routers to expose the camera to the internet. The primary frustration for this camp is the manual update process, arguing that security patches for devices placed in bedrooms and living rooms should be applied automatically.

Key points

  1. A zero-day vulnerability in the TP-Link Tapo C200 camera allowed attackers to bypass authentication and access live video feeds.
  2. The flaw grants full administrative control, enabling an intruder to pan and tilt the camera or view local storage.
  3. Exploitation requires the attacker to be on the same local Wi-Fi network or for the camera to be exposed to the public internet.
  4. TP-Link has released a firmware patch, which users must manually install via the Tapo mobile app.

Sources

Source coverage

5 outlets

2 viewpoints surfaced

Cybersecurity Researchers 50%Consumer Tech Advocates 50%
  1. [1]HackYourMomCybersecurity Researchers

    Vulnerabilities in TP-Link Tapo C200 Cameras Allowed Access to Video Without a Password

    Read on HackYourMom
  2. [2]Infosecurity MagazineCybersecurity Researchers

    Zero-Day Flaw in TP-Link Cameras Enables Eavesdropping

    Read on Infosecurity Magazine
  3. [3]PCMagConsumer Tech Advocates

    A TP-Link Internet Camera Contains a Serious Flaw, Security Researchers Say

    Read on PCMag
  4. [4]CybernewsConsumer Tech Advocates

    TP-Link Tapo C200 flaws could let hackers spy through cameras

    Read on Cybernews
  5. [5]RewterzCybersecurity Researchers

    TP-Link Camera Zero-Days Enable Unauthorized Surveillance

    Read on Rewterz

Comments

Stay informed

Every angle. Every day.

Get Technology stories with full source coverage and perspective breakdowns delivered to your inbox.