PT-2026-103952 · Tp Link · Tapo C200 V5+1
CVE-2026-102369
·
Published
2026-10-01
·
Updated
2026-10-02
CVSS v4.0
8.7
High
| Vector | AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Tapo C120 v1
Tapo C200 V5
Description
Insufficient protection of login challenge data and lack of sanitization of attacker-controlled input processed by the MacTool handler allow an unauthenticated attacker on the same local network to replay login challenge data. This process enables the attacker to obtain an administrative session and activate a privileged service that becomes accessible after a device reboot. By submitting crafted input, the attacker can execute arbitrary commands within the device management process, compromising the confidentiality, integrity, and availability of the device.
Recommendations
Update the firmware for Tapo C120 v1.
Update the firmware for Tapo C200 V5.
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tapo C120 V1
Tapo C200 V5