CVE Tools

CVE-2026-15316

Denial-of-Service via Oversized Encrypted Credential Input in TP-Link Tapo C200

No known exploitation. EPSS puts it in the 13th percentile. A vendor fix is available.

Published Updated Sources: CVE.org, NVD

What to do

The vendor has published a fix. Version details are below where the sources state them.

Steps

Written by AI from the record
  1. Check whether you use a Tapo C200 v5 and record its installed firmware version in the Tapo app or camera management page.
  2. Update affected cameras to firmware 1.4.6; for the v5 release, install V5_1.4.6 Build 260709 Rel.27675n.
  3. Until updated, keep the camera configuration service accessible only from trusted local network devices.
  4. After updating, confirm the camera stays online and HTTPS management access works normally.

What it is

From the CVE record

An improper input validation vulnerability in the configuration service for processing encrypted credential data has been identified in Tapo C200 v5.  An attacker can send oversized crypted ciphertext values that may trigger exception handling failures, due to insufficient validation, causing the affected device to crash or restart. Successful exploitation may temporarily disrupt HTTPS management and monitoring functionality, resulting in a denial-of-service (DoS) condition until the service recovers.

In plain language

Written by AI from the record

Tapo C200 v5 cameras running firmware earlier than 1.4.6 can be forced to restart by someone on your local network, disrupting camera monitoring and management.

Unauthenticated adjacent-network denial of service in the Tapo C200 v5 configuration service: oversized encrypted credential input triggers exception-handling failures and restarts the device.

If you're affected

  • Camera monitoring interruption
  • Management access outage
  • Repeated device restarts
  • Security coverage gaps

Exploitation

Where each signal puts this CVE on the scale from published to confirmed exploited.

EPSS13th
CISA KEV

Not in the catalog. CISA has not confirmed exploitation.

Public exploits

No public exploit or proof of concept found in the sources we track.

EPSS

0.2% chance of exploitation activity in the next 30 days, which ranks it in the 13th percentile of scored CVEs.

Exploit Prediction Scoring System, FIRST.org. A probability, not a confirmation.

Lifecycle

8 events over 17 days, from the signal feeds we watch.

  1. Patch availablerecord updated
  2. Record updated
  3. Record updated
  4. Publishedweakness classified, att&ck mapped, record updated

Affected products

Technical detail

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Scored 6.5 by NVD.

How it is reached

  • Attack Vector AdjacentRequires access to the local network (e.g. same Wi-Fi, Bluetooth)
  • Attack Complexity LowNo special conditions — the attack can be reliably reproduced
  • Privileges Required NoneNo authentication required — anyone can exploit this
  • User Interaction NoneNo user interaction needed — fully automated exploitation

Scope

  • Scope UnchangedImpact is limited to the vulnerable component itself

Impact if exploited

  • Confidentiality NoneNo confidentiality impact
  • Integrity NoneNo integrity impact
  • Availability HighTotal denial of service — the component is completely unavailable

Weaknesses

ATT&CK techniques

Mapped from the weaknesses above (CWE to ATT&CK), not observed in attacks.

Sources

Watch the software you run.

My Stack ranks new CVEs for your products by real-world exploitation, so the next serious one reaches you without reading every advisory.

We'll flag the next CVE, public exploit or patch for Tapo C200 V5, not every advisory.

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store