CVE-2026-15316
Denial-of-Service via Oversized Encrypted Credential Input in TP-Link Tapo C200
No known exploitation. EPSS puts it in the 13th percentile. A vendor fix is available.
What to do
The vendor has published a fix. Version details are below where the sources state them.
Steps
Written by AI from the record- Check whether you use a Tapo C200 v5 and record its installed firmware version in the Tapo app or camera management page.
- Update affected cameras to firmware 1.4.6; for the v5 release, install V5_1.4.6 Build 260709 Rel.27675n.
- Until updated, keep the camera configuration service accessible only from trusted local network devices.
- After updating, confirm the camera stays online and HTTPS management access works normally.
What it is
From the CVE record
An improper input validation vulnerability in the configuration service for processing encrypted credential data has been identified in Tapo C200 v5. An attacker can send oversized crypted ciphertext values that may trigger exception handling failures, due to insufficient validation, causing the affected device to crash or restart. Successful exploitation may temporarily disrupt HTTPS management and monitoring functionality, resulting in a denial-of-service (DoS) condition until the service recovers.
In plain language
Written by AI from the recordTapo C200 v5 cameras running firmware earlier than 1.4.6 can be forced to restart by someone on your local network, disrupting camera monitoring and management.
Unauthenticated adjacent-network denial of service in the Tapo C200 v5 configuration service: oversized encrypted credential input triggers exception-handling failures and restarts the device.
If you're affected
- Camera monitoring interruption
- Management access outage
- Repeated device restarts
- Security coverage gaps
Exploitation
Where each signal puts this CVE on the scale from published to confirmed exploited.
- CISA KEV
Not in the catalog. CISA has not confirmed exploitation.
- Public exploits
No public exploit or proof of concept found in the sources we track.
- EPSS
0.2% chance of exploitation activity in the next 30 days, which ranks it in the 13th percentile of scored CVEs.
Exploit Prediction Scoring System, FIRST.org. A probability, not a confirmation.
Lifecycle
8 events over 17 days, from the signal feeds we watch.
- Patch availablerecord updated
- Record updated
- Record updated
- Publishedweakness classified, att&ck mapped, record updated
Affected products
Technical detail
CVSS 3.1 vector
Open in the CVSS calculatorCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Scored 6.5 by NVD.
How it is reached
- Attack Vector AdjacentRequires access to the local network (e.g. same Wi-Fi, Bluetooth)
- Attack Complexity LowNo special conditions — the attack can be reliably reproduced
- Privileges Required NoneNo authentication required — anyone can exploit this
- User Interaction NoneNo user interaction needed — fully automated exploitation
Scope
- Scope UnchangedImpact is limited to the vulnerable component itself
Impact if exploited
- Confidentiality NoneNo confidentiality impact
- Integrity NoneNo integrity impact
- Availability HighTotal denial of service — the component is completely unavailable
Weaknesses
ATT&CK techniques
Mapped from the weaknesses above (CWE to ATT&CK), not observed in attacks.
- Initial AccessT1190Exploit Public-Facing Applicationlow confidence
Sources
References in the record
In the news
Watch the software you run.
My Stack ranks new CVEs for your products by real-world exploitation, so the next serious one reaches you without reading every advisory.
We'll flag the next CVE, public exploit or patch for Tapo C200 V5, not every advisory.
A free account adds
- The full version matrix and every affected product
- Exploit links, proofs of concept and Metasploit modules
- Email alerts for the products you watch
- The same data over REST API, MCP and CLI