Summary
Opswat discovered two critical vulnerabilities, an authentication bypass (CVE-2026-15315) and a denial-of-service (CVE-2026-15316), in TP-Link Tapo C200 cameras, potentially allowing hackers to spy or crash devices. TP-Link released firmware version V5_1.4.6 on August 18, 2026, to address these flaws, and users are urged to update immediately.