Skip to finding
important · Firmware — Tapo

A local-network peer can replay camera-supplied material to obtain a Tapo administrator session.

Affects

TP-Link Tapo C120 and C200 consumer IP security cameras running vulnerable firmware.

With only LAN access to TCP 443, the attacker asks the camera for authentication material, replays it through another request path, and receives an administrator token without the password.

Detail and 2 sources
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Monday, September 21, 2026