CVE-2026-15315Tp-link · Tapo_c120_firmware
Vulnerability data via NVD (ingested)
Tapo C120 v1 and C200 v5 contain an improper authentication vulnerability within the login authentication verification module. An attacker on the local network can exploit weaknesses in challenge parameter validation to bypass normal authentication controls and obtain administrative session tokens. Successful exploitation may allow an attacker to subsequently execute privileged management actions, enable unauthorized administrative access and temporary disruption of device services, resulting in a denial-of-service (DoS) condition.
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
vuln:CVE-2026-15315os:"Tapo C120 Firmware"More intel sources (5)
vuln:CVE-2026-15315vulnerabilities.cve_id: CVE-2026-15315CVE-2026-15315CVE-2026-15315"CVE-2026-15315" exploit -site:nvd.nist.gov