Description
Tapo C120 v1 and C200 V5
do not adequately protect login challenge data or sanitize
attacker-controlled input processed by the MacTool handler. An unauthenticated
attacker on the same local network can replay login challenge data to obtain an
administrative session, enable a privileged service that becomes accessible
after a reboot, and submit crafted input to execute arbitrary commands within
the device management process.









Successful
exploitation may allow arbitrary command execution on the camera and compromise
the confidentiality, integrity, and availability of the affected device.
Exploitation requires access from the same local network, replay of the login
challenge data, activation of the privileged service, and a device reboot.
Published: 2026-10-01
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Tp-link
Tp-link tapo C120 V1
Tp-link tapo C200 V5
Vendors & Products Tp-link
Tp-link tapo C120 V1
Tp-link tapo C200 V5

Thu, 01 Oct 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 17:45:00 +0000

Type Values Removed Values Added
Description Tapo C120 v1 and C200 V5 do not adequately protect login challenge data or sanitize attacker-controlled input processed by the MacTool handler. An unauthenticated attacker on the same local network can replay login challenge data to obtain an administrative session, enable a privileged service that becomes accessible after a reboot, and submit crafted input to execute arbitrary commands within the device management process. Successful exploitation may allow arbitrary command execution on the camera and compromise the confidentiality, integrity, and availability of the affected device. Exploitation requires access from the same local network, replay of the login challenge data, activation of the privileged service, and a device reboot.
Title Unauthenticated Remote Code Execution via MacTool Command Injection in TP-Link Tapo C120 & C200
Weaknesses CWE-287
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Tp-link Tapo C120 V1 Tapo C200 V5
cve-icon MITRE

Status: PUBLISHED

Assigner: TPLink

Published:

Updated: 2026-10-01T18:08:05.015Z

Reserved: 2026-09-28T23:02:41.717Z

Link: CVE-2026-102369

cve-icon Vulnrichment

Updated: 2026-10-01T18:08:00.590Z

cve-icon NVD

Status : Deferred

Published: 2026-10-01T18:17:12.400

Modified: 2026-10-01T20:36:38.330

Link: CVE-2026-102369

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T19:33:16Z

Weaknesses