{
  "id": 7997579,
  "title": "TP-Link camera flaws expose feeds to unauthorised access",
  "url": "https://urgent.news/2026/09/17/tp-link-camera-flaws-expose-feeds-to-unauthorised-access",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-17T07:07:25.000Z",
  "source": {
    "name": "Arabian Post",
    "slug": "arabian-post",
    "url": "https://thearabianpost.com/tp-link-camera-flaws-expose-feeds-to-unauthorised-access/"
  },
  "original_language": "en",
  "account": "Two security flaws in TP-Link Tapo cameras have been discovered by security researchers, allowing attackers to bypass authentication, gain administrator access, and potentially view live video or stored recordings of unsuspecting users. The vulnerabilities, identified as CVE-2026-15315 and CVE-2026-15316, are present in certain models of the Tapo C200 security camera. TP-Link has provided firmware fixes for the affected models and advised users to install the most recent updates. The more critical flaw, CVE-2026-15315, involves an authentication bypass in the camera's local management interface, enabling an attacker with network access to obtain a valid administrative session without needing to know the user's password. This level of access could permit the alteration of device settings and the misuse of restricted management functions, potentially exposing privacy-sensitive information such as live streams and recorded videos. The severity of CVE-2026-15315 is rated as high, with a CVSS score of 8.7. The second vulnerability, CVE-2026-15316, concerns inadequate validation of encrypted credential data during configuration. An attacker with network access could submit an oversized encrypted credential value, causing a denial-of-service condition, where the HTTPS service crashes and interrupts management and monitoring until the service recovers. TP-Link has assigned this flaw a CVSS score of 7.1, also classified as high. The company has issued fixed firmware versions for the impacted devices and urged users to install the updated software to protect against these security risks.",
  "summary": "Two security flaws in TP-Link Tapo cameras can let attackers bypass authentication, gain administrator access and potentially view live video or stored recordings, security researchers have disclosed. Cybersecurity company OPSWAT said the vulnerabilities, tracked as CVE-2026-15315 and CVE-2026-15316, were identified during research into the Tapo C200 security camera. TP-Link has issued firmware…",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}