These popular TP-Link home security cameras could be hacked to spy on you while you sleep, experts warn
A passwordless login bypass in TP-Link's Tapo C200 and C120 cameras can expose your live feed to anyone on the same network, and a fix is already available to download
Two high-severity cybersecurity flaws have been discovered in TP-Link's popular Tapo C200 and C120 home security cameras, potentially allowing hackers to spy on users while they sleep. Cybersecurity firm OPSWAT found that an attacker on the same network could gain full administrative access to the cameras without needing the owner's credentials, granting them access to live video feeds, recorded footage, and the ability to alter camera settings.
The more serious issue involves a local login bypass that does not require authentication, allowing an attacker to log in as the camera's administrator. Both vulnerabilities have been patched in the latest firmware updates, but approximately 3,000 units of the C200 and over 5,000 C120 units have not yet been updated.
Written by urgent.news from TechRadar's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.