CVE-2026-102369
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Summary
Tapo C120 v1 and C200 V5 do not adequately protect login challenge data or sanitize attacker-controlled input processed by the MacTool handler. An unauthenticated attacker on the same local network can replay login challenge data to obtain an administrative session, enable a privileged service that becomes accessible after a reboot, and submit crafted input to execute arbitrary commands within the device management process.
Successful exploitation may allow arbitrary command execution on the camera and compromise the confidentiality, integrity, and availability of the affected device. Exploitation requires access from the same local network, replay of the login challenge data, activation of the privileged service, and a device reboot.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| TP-Link Systems Inc. | Tapo C200 v5 | 0 < V5_1.4.6 Build 260709 Rel.27675n | affected |
| TP-Link Systems Inc. | Tapo C120 v1 | 0 < V1_1.9.4 Build 260813 Rel.79754n | affected |
Weaknesses
- CWE-287: CWE-287 Improper Authentication
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: total
References
- https://www.tp-link.com/us/support/download/tapo-c200/v5/#Firmware-Release-Notes
- https://www.tp-link.com/en/support/download/tapo-c200/v5/#Firmware-Release-Notes
- https://www.tp-link.com/us/support/download/tapo-c120/v1.26/#Firmware-Release-Notes
- https://www.tp-link.com/en/support/download/tapo-c120/v1.26/#Firmware-Release-Notes
- https://www.tp-link.com/us/support/faq/5321/
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.