important · Firmware — Tapo
A local-network peer can replay camera-supplied material to obtain a Tapo administrator session.
Affects
TP-Link Tapo C120 and C200 consumer IP security cameras running vulnerable firmware.
With only LAN access to TCP 443, the attacker asks the camera for authentication material, replays it through another request path, and receives an administrator token without the password.
Detail and 2 sources
OPSWAT demonstrated the bypass, and TP-Link has published fixed firmware.