Skip to finding
important · Wi-Fi

A same-LAN attacker can turn replayed Tapo onboarding data into command execution on C120 and C200 cameras.

Affects

TP-Link Tapo C120 and C200, Wi-Fi-connected home security cameras running embedded firmware.

The chain applies to Tapo C120 V1 and C200 V5 cameras reachable from the same local network.

Detail and 2 sources

Replayed login-challenge data yields an administrative session that can enable a privileged service and reach command execution through unsanitized MacTool input.

The chain is model-specific and same-LAN only; TP-Link published corrected firmware, but that fix was not read for this brief.

Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Saturday, October 3, 2026