8.8
CVE-2026-15315
- EPSS 0.24%
- Veröffentlicht 18.08.2026 21:24:59
- Zuletzt bearbeitet 04.09.2026 17:39:06
- Erkennungen
Unauthenticated Administrative Authentication Bypass via device_confirm Replay in TP-Link Tapo C120 and C200
Tapo C120 v1 and C200 v5 contain an improper authentication vulnerability within the login authentication verification module. An attacker on the local network can exploit weaknesses in challenge parameter validation to bypass normal authentication controls and obtain administrative session tokens. Successful exploitation may allow an attacker to subsequently execute privileged management actions, enable unauthorized administrative access and temporary disruption of device services, resulting in a denial-of-service (DoS) condition.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Tp-link ≫ Tapo C120 Firmware Version < 1.9.3
Tp-link ≫ Tapo C200 Firmware Version < 1.4.6
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.24% | 0.155 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| f23511db-6c3e-4e32-a477-6aa17d310630 | 8.7 | 0 | 0 |
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
CWE-287 Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
https://www.tp-link.com/us/support/download/tapo-c200/v5/
https://www.tp-link.com/en/support/download/tapo-c200/v5/
https://www.tp-link.com/us/support/faq/5248/
https://www.tp-link.com/en/support/download/tapo-c120/v1.26/#Firmware-Release-Notes
https://www.tp-link.com/us/support/download/tapo-c120/v1.26/#Firmware-Release-Notes