important · Wi-Fi
A same-LAN attacker can turn replayed Tapo onboarding data into command execution on C120 and C200 cameras.
Affects
TP-Link Tapo C120 and C200, Wi-Fi-connected home security cameras running embedded firmware.
The chain applies to Tapo C120 V1 and C200 V5 cameras reachable from the same local network.
Detail and 2 sources
Replayed login-challenge data yields an administrative session that can enable a privileged service and reach command execution through unsanitized MacTool input.
The chain is model-specific and same-LAN only; TP-Link published corrected firmware, but that fix was not read for this brief.