Tapo C120 v1 and C200 v5
do not enforce authentication for do method HTTPS onboarding connect actions
after initial setup. An unauthenticated adjacent
attacker can submit unauthorized wireless configuration parameters, causing the
camera to attempt connection to a different network.
Successful
exploitation disconnects the camera from its intended wireless network, making
it unreachable on its management address, resulting in a denial-of-service
condition.
do not enforce authentication for do method HTTPS onboarding connect actions
after initial setup. An unauthenticated adjacent
attacker can submit unauthorized wireless configuration parameters, causing the
camera to attempt connection to a different network.
Successful
exploitation disconnects the camera from its intended wireless network, making
it unreachable on its management address, resulting in a denial-of-service
condition.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 01 Oct 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Tapo C120 v1 and C200 v5 do not enforce authentication for do method HTTPS onboarding connect actions after initial setup. An unauthenticated adjacent attacker can submit unauthorized wireless configuration parameters, causing the camera to attempt connection to a different network. Successful exploitation disconnects the camera from its intended wireless network, making it unreachable on its management address, resulting in a denial-of-service condition. | |
| Title | Unauthenticated do Method Onboarding Connect Allows Wi‑Fi Reconfiguration Denial of Service Vulnerability in TP-Link Tapo C120 & C200 | |
| Weaknesses | CWE-306 | |
| References |
|
|
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: TPLink
Published:
Updated: 2026-10-01T18:08:30.649Z
Reserved: 2026-08-24T20:46:19.845Z
Link: CVE-2026-78578
No data.
Status : Received
Published: 2026-10-01T18:17:27.997
Modified: 2026-10-01T18:17:27.997
Link: CVE-2026-78578
No data.
OpenCVE Enrichment
No data.
Weaknesses