{"id":404858,"date":"2026-08-22T04:47:45","date_gmt":"2026-08-22T04:47:45","guid":{"rendered":"https:\/\/malwaretips.com\/blogs\/?p=404858"},"modified":"2026-08-22T04:47:45","modified_gmt":"2026-08-22T04:47:45","slug":"tapo-c200-firmware-1-4-6","status":"publish","type":"post","link":"https:\/\/malwaretips.com\/blogs\/tapo-c200-firmware-1-4-6\/","title":{"rendered":"The Tapo C200 still needs 1.4.6"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">The white dome on the shelf is watching the hallway, the register, or the front porch. TP-Link&#8217;s August advisory says some Tapo C200 cameras will hand an admin session to someone already on your Wi-Fi who can replay a device_confirm exchange the firmware should have rejected. That is a next-room problem, not a stranger typing your public IP. The fix is firmware 1.4.6 Build 260709 on hardware V5. If Device Info still reads an older build, the Tapo app is the patch.<\/p><div id=\"mwtad3798494013\" class=\"gas_fallback-ad_309684--placement_400588\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3957935887\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"1536\" height=\"1024\" src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/do-this-now-tapo-overview.png\" alt=\"Tapo C200 on a shelf next to a phone showing Firmware Version 1.4.6 Build 260709\" class=\"wp-image-404856\" title=\"\" srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/do-this-now-tapo-overview.png 1536w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/do-this-now-tapo-overview-300x200.png 300w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/do-this-now-tapo-overview-1024x683.png 1024w\" sizes=\"auto, (max-width: 1536px) 100vw, 1536px\" \/><figcaption class=\"wp-element-caption\">The phone should show 1.4.6 Build 260709.<\/figcaption><\/figure>\n\n\n\n<div id=\"mwtad1972984622\" class=\"gas_fallback-ad_309747-ad_309691-placement_400589\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"9589536513\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2 class=\"wp-block-heading\">Overview<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">What broke<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">TP-Link last updated the <a href=\"https:\/\/www.tp-link.com\/us\/support\/faq\/5248\/\" target=\"_blank\" rel=\"noopener\">security advisory for Tapo cameras<\/a> on 18 August 2026. The lead bug is <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-15315\" target=\"_blank\" rel=\"noopener\">CVE-2026-15315<\/a>, an unauthenticated administrative authentication bypass via device_confirm replay on Tapo C200 hardware V5. A LAN attacker who can capture and replay that exchange can obtain admin session tokens. TP-Link scores it CVSS v4.0 8.7 High. Adjacent means the Wi-Fi or Ethernet, not a random host on the public internet.<\/p>\n\n\n\n<div id=\"mwtad1463208253\" class=\"mwtadp1 mwtadentity-placement\" style=\"margin-top: 50px;margin-bottom: 50px;\"> \r\n<ins class=\"adsbygoogle\"\r\n     style=\"display:block; text-align:center;\"\r\n     data-ad-layout=\"in-article\"\r\n     data-ad-format=\"fluid\"\r\n     data-ad-client=\"ca-pub-7750719144850257\"\r\n     data-ad-slot=\"7312657698\"><\/ins>\r\n <\/div><p class=\"wp-block-paragraph\">Replay, in English, is taking a packet the camera already accepted once and sending it again so the box treats the attacker as an admin. device_confirm is the handshake the firmware was supposed to treat as single-use. With an admin session token, they can change streams, passwords, and where the lens points the same way you can from the Tapo app.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The same advisory also names <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-15316\" target=\"_blank\" rel=\"noopener\">CVE-2026-15316<\/a>, a denial-of-service from oversized ciphertext, scored 7.1. One firmware pass closes both. Lead on the auth bypass.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">TP-Link has not said 15315 or 15316 is being used in the wild. CISA has not listed either CVE on the <a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog\" target=\"_blank\" rel=\"noopener\">Known Exploited Vulnerabilities catalog<\/a>. The firmware is posted. That is the cheap window.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Who is in range<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Anyone running a Tapo C200 hardware V5 below V5_1.4.6 Build 260709 Rel.27675n. The sticker on the base, or Device Info in the Tapo app, names the hardware version. V5 is this brief. Older revisions are different boards. Do not flash a V5 file onto them.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The shop waiting-room C200 and the porch cam at home are the same product. A guest SSID does not put you out of range if the camera still shares the LAN. A neighbor with last year&#8217;s Wi-Fi password, a compromised laptop, or a tablet left on the shop Wi-Fi: that is the cast for a LAN replay.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If Device Info already shows 1.4.6 Build 260709, confirm the string anyway. &#8220;I turned auto-update on last year&#8221; is not a version number. Other Tapo models and TP-Link routers are not this advisory.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">What the vendor shipped<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The fixed firmware is V5_1.4.6 Build 260709 Rel.27675n for Tapo C200 hardware V5. TP-Link published the US package on 17 August 2026 on the <a href=\"https:\/\/www.tp-link.com\/us\/support\/download\/tapo-c200\/\" target=\"_blank\" rel=\"noopener\">US download page for Tapo C200<\/a>. The file string is Tapo C200(US)_V5_1.4.6 Build 260709. Use the site for the country where you bought the camera.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Preferred path: Tapo app, open the C200, gear or Settings, Firmware Update. Let the app pull 1.4.6 Build 260709, then confirm Device Info.<\/li>\n<li>Fallback: download the V5 package from the US support page and flash per TP-Link&#8217;s FAQ.<\/li>\n<li>After install: change a default camera password, and turn off unused RTSP or ONVIF.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">If Firmware Update offers a later V5 build for the same hardware, take that. Do not stop below 1.4.6 Build 260709.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">What this is not<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Not an Archer C20 or Archer AXE75 router story. Those are different boards with their own firmware pages. Do not flash camera firmware onto a router.<\/li>\n<li>Not the crash-only Tapo C100 RTSP advisories. C100 DoS is a different product and a different CVE set. This brief is C200 V5 and the admin-bypass row.<\/li>\n<li>Not a WAN unauthenticated remote-code exploit. TP-Link described a LAN attacker who can replay device_confirm.<\/li>\n<li>Not on CISA KEV. TP-Link has not claimed in-the-wild use.<\/li>\n<li>Not patched by updating a phone OS, a PC, or the Tapo app alone. The firmware on the camera is the close.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">The patch is out. Firmware Update is already in the Tapo app. That is the cheap window.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"1536\" height=\"1024\" src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/do-this-now-tapo-house.png\" alt=\"Do This Now card: Update the Tapo C200 to 1.4.6, in range You plus the shop, urgency This week, then Tapo app\" class=\"wp-image-404857\" title=\"\" srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/do-this-now-tapo-house.png 1536w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/do-this-now-tapo-house-300x200.png 300w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/08\/do-this-now-tapo-house-1024x683.png 1024w\" sizes=\"auto, (max-width: 1536px) 100vw, 1536px\" \/><figcaption class=\"wp-element-caption\">Update the Tapo C200.<\/figcaption><\/figure>\n\n\n\n<div id=\"mwtad2314314390\" class=\"gas_fallback-ad_309748-ad_309691-placement_400590\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3906789406\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2 class=\"wp-block-heading\">Do This Now<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>In range:<\/strong> You, plus the shop. Tapo C200 hardware V5 below V5_1.4.6 Build 260709 Rel.27675n.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Urgency:<\/strong> This week. LAN replay, not internet-wide. The firmware is sitting there.<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Confirm the model is Tapo C200 and the hardware is V5. Check the sticker on the base, or open the Tapo app, tap the camera, gear or Settings, Device Info.<\/li>\n<li>In the same camera settings, open Firmware Update. Install 1.4.6 Build 260709. Leave the camera powered. When it comes back, open Device Info again and read the firmware string.<\/li>\n<li>Change the camera password if it is still the default. Turn off unused RTSP and ONVIF if you do not stream to a third-party NVR. Repeat for every other C200 V5 on the LAN.<\/li>\n<\/ol>\n\n\n\n<div id=\"mwtad2420376608\" class=\"gas_fallback-ad_309749-ad_309691-placement_400591\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"5354318971\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2 class=\"wp-block-heading\">Who can skip<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>You do not own a Tapo C200.<\/li>\n<li>The sticker or Device Info is not hardware V5. Do not flash the V5 file onto it.<\/li>\n<li>Device Info already shows 1.4.6 Build 260709, or a later V5 build TP-Link lists for this hardware, and you confirmed it after the camera rebooted.<\/li>\n<li>A Tapo C100, C101, or another Tapo model. This advisory names C200 V5 for the 15315 bypass.<\/li>\n<li>An Archer C20, Archer AXE75, or any other TP-Link router. Different product, different download page.<\/li>\n<\/ul>\n\n\n\n<div id=\"mwtad1593389792\" class=\"gas_fallback-ad_309750-ad_309691-placement_400592\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"4041237300\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2 class=\"wp-block-heading\">Why it matters<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Own the camera admin session and you own the live view, the cloud clips, the motion alerts, and where the lens points. A replay that hands out admin tokens is how a guest on the Wi-Fi stops being &#8220;just on the network&#8221; and starts being the person who can silence or redirect the cam.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">TP-Link&#8217;s attacker is already next to you on the LAN. A guest who stayed on after the party. A neighbor who still has last year&#8217;s password. A shop tablet that never left the waiting-room Wi-Fi. The hole is not a stranger typing your WAN IP. It is the next room, plus a device_confirm exchange the firmware should have treated as single-use.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">CISA has not added 15315 or 15316 to KEV. TP-Link did not claim a victim count and did not say either bug is in the wild. Waiting is still how a High LAN admin bypass sits on the camera every hallway and register trusts. The shop owner is often the only person who ever opens the Tapo app. If the camera password is still the default, treat the firmware flash and a new password as the same night&#8217;s work.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">RTSP and ONVIF are useful when you feed a home NVR. They are also extra doors on the LAN. If you never set those up, leave them off after the update. One less surface for the next advisory.<\/p>\n\n\n\n<div id=\"mwtad134082934\" class=\"gas_fallback-ad_309751-ad_309691-placement_400593\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3690286463\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2 class=\"wp-block-heading\">The bottom line<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">On the phone with the Tapo app<\/h3>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Put the phone on the same Wi-Fi as the camera. Cellular alone will not reach a camera that only talks on the LAN for local setup.<\/li>\n<li>Open the Tapo app. Tap the C200 tile. Tap the gear or Settings in the corner.<\/li>\n<li>Open Device Info first. Write down the model, the hardware version, and the current firmware string. You need hardware V5 for this file. Stop if the sticker or Device Info says a different hardware revision.<\/li>\n<li>Go back one screen and open Firmware Update. Tap Check for updates or Update. Wait for 1.4.6 Build 260709. Leave the camera plugged in. A mid-flash unplug is how you get a brick.<\/li>\n<li>When the camera comes back online, open Device Info again. The line you want is 1.4.6 Build 260709, matching V5_1.4.6 Build 260709 Rel.27675n on the advisory. Trust Device Info, not the splash.<\/li>\n<\/ol>\n\n\n\n<h3 class=\"wp-block-heading\">What you should see<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Firmware Update should name the Tapo C200, then either say you are current or offer a download. After install, Device Info should read Firmware Version 1.4.6 Build 260709. The phone screen in a good pass looks like a clean &#8220;up to date&#8221; page with that exact build string under it. If you still see 1.4.5, 1.3.x, or any string below 1.4.6 Build 260709, stay on Firmware Update and try again.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">If Firmware Update is missing or stuck<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Force-close the Tapo app and reopen it on the camera&#8217;s Wi-Fi. Sign out and back into the TP-Link ID if the camera shows offline. A shop network that blocks the camera from reaching TP-Link will sit on &#8220;checking&#8221; forever. Manual install is the fallback: open the <a href=\"https:\/\/www.tp-link.com\/us\/support\/download\/tapo-c200\/\" target=\"_blank\" rel=\"noopener\">US Tapo C200 download page<\/a>, pick hardware V5, download Tapo C200(US)_V5_1.4.6 Build 260709, and follow TP-Link&#8217;s flash steps in the FAQ.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Do not grab a file from a random &#8220;camera update&#8221; site. Do not flash a C100 package onto a C200, or a V4 file onto V5. Do not put a non-US regional bin on a US unit unless TP-Link&#8217;s page for your purchase country says that is the match.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Password, RTSP, and the other cam<\/h3>\n\n\n\n<ol class=\"wp-block-list\">\n<li>In camera settings, change the device password if it is still the factory default or a reused Wi-Fi phrase.<\/li>\n<li>If you do not use a third-party NVR, turn off RTSP and ONVIF. If you do use them, change those stream passwords the same night.<\/li>\n<li>The porch cam, the shop waiting-room C200, the spare on the shelf: same Device Info and Firmware Update path tonight if the sticker is V5.<\/li>\n<li>If a camera is a C100 or another Tapo model, leave it. Hunt that model&#8217;s own advisory instead of borrowing this file.<\/li>\n<\/ol>\n\n\n\n<h3 class=\"wp-block-heading\">When you are done<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Device Info shows 1.4.6 Build 260709 on every C200 V5 in the house or shop. The camera password is no longer the default. Unused RTSP and ONVIF are off. You needed a new firmware string. You have it.<\/p>\n\n<div id=\"mwtad2913401585\" class=\"gas_fallback-ad_176819-ad_309691-placement_400595\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"8386082122\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>The white dome on the shelf is watching the hallway, the register, or the front porch. TP-Link&#8217;s August advisory says some Tapo C200 cameras will hand an admin session to someone already on your Wi-Fi &#8230; <\/p>\n<p class=\"read-more-container\"><a title=\"The Tapo C200 still needs 1.4.6\" class=\"read-more button\" href=\"https:\/\/malwaretips.com\/blogs\/tapo-c200-firmware-1-4-6\/#more-404858\" aria-label=\"Read more about The Tapo C200 still needs 1.4.6\">Read more<\/a><\/p>\n","protected":false},"author":51,"featured_media":404856,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3605],"tags":[],"class_list":["post-404858","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","masonry-post","generate-columns","tablet-grid-50","mobile-grid-100","grid-parent","grid-50","resize-featured-image"],"_links":{"self":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/404858","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/users\/51"}],"replies":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/comments?post=404858"}],"version-history":[{"count":1,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/404858\/revisions"}],"predecessor-version":[{"id":404886,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/404858\/revisions\/404886"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/media\/404856"}],"wp:attachment":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/media?parent=404858"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/categories?post=404858"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/tags?post=404858"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}