VendorsTP-Linktapo_c200_firmwareall versions
Vulnerabilities

TP-Link Tapo c200 Firmware

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

11CVEs
CVE-2021-4045
TP-LINK Tapo C200 remote code execution vulnerability
Published 2022-03-07 · Modified
10.01 PoCEPSS 0.724
CVE-2026-15315
Unauthenticated Administrative Authentication Bypass via device_confirm Replay in TP-Link Tapo C200
Published 2026-08-18 · Analyzed
8.8EPSS 0.003
CVE-2025-8065
Remote Code Execution via Stack-based Buffer Overflow in ONVIF SOAP Parser in TP-Link Tapo C200 and C520WS
Published 2025-12-20 · Modified
8.7EPSS 0.005
CVE-2025-14300
Unauthenticated Access to connectAP API Endpoint on Tapo C100, C200 & C425
Published 2025-12-20 · Modified
8.7EPSS 0.004
CVE-2026-12760
Denial-of-Service Vulnerability via Malformed IPv4 Fragmentation Handling in TP-Link Tapo C200
Published 2026-06-24 · Analyzed
7.1EPSS 0.004
CVE-2026-1871
Authenticated Stack-based Buffer Overflow in RTSP Authentication of Tapo C200
Published 2026-06-02 · Analyzed
7.1EPSS 0.003
CVE-2025-14299
Improper Content-Length Validation in HTTPS Requests on Tapo C200
Published 2025-12-20 · Analyzed
7.1EPSS 0.002
CVE-2026-15316
Denial-of-Service via Oversized Encrypted Credential Input in TP-Link Tapo C200
Published 2026-08-18 · Analyzed
7.1EPSS 0.002
CVE-2020-11445
TP-Link cloud cameras through 2020-02-09 allow remote attackers to bypass authentication and obtain sensitive information via vectors involving a Wi-Fi session with GPS enabled, aka CNVD-2020-04855.
Published 2020-04-01 · Modified
5.3EPSS 0.018
CVE-2023-49515
Insecure Permissiosn vulnerability in TP Link TC70 and C200 WIFI Camera v.3 firmware v.1.3.4 and fixed in v.1.3.11 allows a physically proximate attacker to obtain sensitive information via a connection to the UART pin components.
Published 2024-01-17 · Modified
4.6EPSS 0.004
CVE-2023-27126
The AES Key-IV pair used by the TP-Link TAPO C200 camera V3 (EU) on firmware version 1.1.22 Build 220725 is reused across all cameras. An attacker with physical access to a camera is able to extract and decrypt sensitive data containing the Wifi password and the TP-LINK account credential of the victim.
Published 2023-06-06 · Modified
4.6EPSS 0.004