CVE-2026-15315 PUBLISHED

Unauthenticated Administrative Authentication Bypass via device_confirm Replay in TP-Link Tapo C200

Assigner: TPLink
Reserved: 09.07.2026 Published: 18.08.2026 Updated: 18.08.2026

Tapo C200 v5 contains an improper authentication vulnerability within the login authentication verification module. An attacker on the local network can exploit weaknesses in challenge parameter validation to bypass normal authentication controls and obtain administrative session tokens.

Successful exploitation may allow an attacker to subsequently execute privileged management actions, enable unauthorized administrative access and temporary disruption of device services, resulting in a denial-of-service (DoS) condition.

Metrics

CVSS Vector: CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.7

Product Status

Vendor TP-Link Systems Inc.
Product Tapo C200 v5
Versions Default: unaffected
  • affected from 0 to V5_1.4.6 Build 260709 Rel.27675n (excl.)

Credits

  • Thai Do (Lio) and Khoi Tran (KayTii) from OPSWAT finder

References

Problem Types

  • CWE-287 Improper Authentication CWE

Impacts

  • CAPEC-115 Authentication Bypass