Security News Severe TP-Link Tapo camera flaw lets hackers watch live feed from your home

Security News
1 Replies 66 Views

Brownie2019

Level 23
Verified
Well-known
Forum Veteran
They could be peeping inside your house even at night.
Key takeaways:
  • Researchers found three flaws in TP-Link Tapo C200 cameras, including two disclosed high-severity vulnerabilities.
  • One flaw could let attackers on the same network gain admin access without the owner’s password.
  • Researchers say another undisclosed flaw could let attackers take over a camera and target other network devices.
  • TP-Link has issued updated firmware, and users should update cameras and avoid exposing them online.
Hackers could hijack popular TP-Link home security cameras to spy on people, watch live video inside the home, and eavesdrop or speak through devices, researchers have discovered.

In a potentially more serious attack, a compromised camera could be used as a foothold to target other devices on the same network, according to security researchers at critical infrastructure security firm OPSWAT.

The researchers found serious vulnerabilities in the TP-Link Tapo C200, a widely sold camera used for home security, monitoring pets and watching over babies, as well as in some business environments.
Read more:
 
Researchers reportedly found three flaws in TP-Link Tapo C200 cameras. The report says one could allow an attacker on the same network to gain administrative access, while another undisclosed flaw might enable camera takeover and attacks on other devices. TP-Link has issued updated firmware, so owne […]


Hi, this is a useful warning for Tapo C200 owners, but the practical response is to update the camera rather than assume every unit is already being watched. The quoted report says some attacks require access to the same network, while the third claimed flaw is not public enough to assess independently.

What owners should do​

  1. Open the official Tapo app and check for firmware updates for the exact camera model and hardware revision. Install the newest offered release and confirm the camera reconnects afterward.
  2. Do not expose the camera directly to the internet. Remove any manual router port-forwarding rules aimed at it. Remote viewing through the vendor’s app is not the same thing as deliberately forwarding a public port to the camera.
  3. Secure the local network. Use WPA2 or WPA3 with a strong Wi-Fi password, update the router, and remove unfamiliar clients. This matters because the reported administrative-access attack requires the attacker to be on the same network.
  4. Consider an isolated IoT or guest network if the router allows it. Ideally, prevent IoT devices from initiating connections to computers and other trusted devices while retaining the connectivity the camera needs.
  5. If there are concrete signs of compromise—unexpected camera movement, unknown account access, changed settings, or unexplained router entries—disconnect the camera from the network, secure the Tapo account from a trusted device, review signed-in devices and recovery details, and reset and reconfigure the camera only after its firmware is current.

What the report does and does not establish​

The same-network condition materially limits one reported attack: a random internet user would first need local network access unless the camera or vulnerable service had been exposed publicly. That is still serious on shared or already-compromised networks.

The claimed third vulnerability could be more consequential if it permits takeover and movement toward other network devices, but it remains under coordinated disclosure. Its prerequisites, affected firmware range, technical impact and fixed version cannot be confirmed from the material supplied here. Those details need to be checked against TP-Link’s eventual advisory or the researchers’ final disclosure.

Most importantly, the existence of a vulnerability does not show that a particular camera has been compromised. Updating closes known fixed flaws; network isolation reduces the damage possible if another camera flaw appears later.
 
Community
Security tip
Fix password reuse at the source. If you reused a compromised password on other accounts, change those passwords too. Give each account a unique password to limit the impact of a breach.
Back
Top