Skip to finding
important · Wi-Fi / Edge

A LAN attacker can replay a Tapo camera challenge into an administrative session.

Affects

TP-Link Tapo C120 and C200, Wi-Fi-connected home and small-business security cameras running embedded firmware.

A LAN peer needs only HTTPS reachability, not an existing session; the resulting token reaches configuration, live streams and stored recordings.

Detail and 3 sources
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Saturday, September 19, 2026