CVE-2026-78577 (GCVE-0-2026-78577)

Vulnerability from cvelistv5 – Published: 2026-10-01 17:41 – Updated: 2026-10-01 18:08
VLAI
Title
Unauthenticated Onboarding Scan Information Disclosure in TP-Link Tapo C120 & C200
Summary
Tapo C120 v1 and C200 V5 contain a vulnerability in the HTTPS onboarding scan function due to missing authentication. After initial setup, an unauthenticated attacker on the same local network can invoke the scan action and retrieve nearby wireless access-point metadata, including SSIDs, BSSIDs, authentication and encryption modes, and signal-strength information. Successful exploitation may disclose information about the wireless environment surrounding the camera, allowing an attacker to learn elements of the local wireless topology.
SSVC
Exploitation: none Automatable: no Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-01 18:08 UTC
CWE
  • CWE-306 - Missing authentication for critical function
Impacted products
Vendor Product Version
TP-Link Systems Inc. Tapo C200 v5 Affected: 0 , < V5_1.4.6 Build 260709 Rel.27675n (custom)
Create a notification for this product.
TP-Link Systems Inc. Tapo C120 v1 Affected: 0 , < V1_1.9.4 Build 260813 Rel.79754n (custom)
Create a notification for this product.
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-78577",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-10-01T18:08:50.711151Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-10-01T18:08:59.956Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Tapo C200 v5",
          "vendor": "TP-Link Systems Inc.",
          "versions": [
            {
              "lessThan": "V5_1.4.6 Build 260709 Rel.27675n",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unaffected",
          "product": "Tapo C120 v1",
          "vendor": "TP-Link Systems Inc.",
          "versions": [
            {
              "lessThan": "V1_1.9.4 Build 260813 Rel.79754n",
              "status": "affected",
              "version": "0",
              "versionType": "custom"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "finder",
          "value": "Thai Do (Lio) and Khoi Tran (KayTii) from OPSWAT"
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eTapo C120 v1 and C200 V5\ncontain a vulnerability in the HTTPS onboarding scan function due to missing authentication.\nAfter initial setup, an unauthenticated attacker on the same local network can\ninvoke the scan action and retrieve nearby wireless access-point metadata,\nincluding SSIDs, BSSIDs, authentication and encryption modes, and\nsignal-strength information.\u003c/p\u003e\u003cp\u003e\n\n\u003c/p\u003e\u003cp\u003eSuccessful\nexploitation may disclose information about the wireless environment\nsurrounding the camera, allowing an attacker to learn elements of the local\nwireless topology.\u0026nbsp;\u003cb\u003e\u003c/b\u003e\u003c/p\u003e"
            }
          ],
          "value": "Tapo C120 v1 and C200 V5\ncontain a vulnerability in the HTTPS onboarding scan function due to missing authentication.\nAfter initial setup, an unauthenticated attacker on the same local network can\ninvoke the scan action and retrieve nearby wireless access-point metadata,\nincluding SSIDs, BSSIDs, authentication and encryption modes, and\nsignal-strength information.\n\n\n\n\n\n\n\n\n\nSuccessful\nexploitation may disclose information about the wireless environment\nsurrounding the camera, allowing an attacker to learn elements of the local\nwireless topology."
        }
      ],
      "impacts": [
        {
          "capecId": "CAPEC-1",
          "descriptions": [
            {
              "lang": "en",
              "value": "CAPEC-1 Accessing Functionality Not Properly Constrained by ACLs"
            }
          ]
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "ADJACENT",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "exploitMaturity": "NOT_DEFINED",
            "privilegesRequired": "NONE",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N",
            "version": "4.0",
            "vulnAvailabilityImpact": "NONE",
            "vulnConfidentialityImpact": "LOW",
            "vulnIntegrityImpact": "NONE",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-306",
              "description": "CWE-306 Missing authentication for critical function",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-10-01T17:41:49.774Z",
        "orgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
        "shortName": "TPLink"
      },
      "references": [
        {
          "tags": [
            "patch"
          ],
          "url": "https://www.tp-link.com/us/support/download/tapo-c200/v5/#Firmware-Release-Notes"
        },
        {
          "tags": [
            "patch"
          ],
          "url": "https://www.tp-link.com/en/support/download/tapo-c200/v5/#Firmware-Release-Notes"
        },
        {
          "tags": [
            "patch"
          ],
          "url": "https://www.tp-link.com/us/support/download/tapo-c120/v1.26/#Firmware-Release-Notes"
        },
        {
          "tags": [
            "patch"
          ],
          "url": "https://www.tp-link.com/en/support/download/tapo-c120/v1.26/#Firmware-Release-Notes"
        },
        {
          "tags": [
            "vendor-advisory"
          ],
          "url": "https://www.tp-link.com/us/support/faq/5321/"
        }
      ],
      "source": {
        "discovery": "UNKNOWN"
      },
      "title": "Unauthenticated Onboarding Scan Information Disclosure in TP-Link Tapo C120 \u0026 C200",
      "x_generator": {
        "engine": "Vulnogram 1.0.5"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
    "assignerShortName": "TPLink",
    "cveId": "CVE-2026-78577",
    "datePublished": "2026-10-01T17:41:49.774Z",
    "dateReserved": "2026-08-24T20:46:18.534Z",
    "dateUpdated": "2026-10-01T18:08:59.956Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "vulnerability-lookup:meta": {
    "epss": {
      "cve": "CVE-2026-78577",
      "date": "2026-10-02",
      "epss": "0.00148",
      "percentile": "0.03411"
    },
    "nvd": {
      "cve": {
        "affected": [
          {
            "affectedData": [
              {
                "defaultStatus": "unaffected",
                "product": "Tapo C200 v5",
                "vendor": "TP-Link Systems Inc.",
                "versions": [
                  {
                    "lessThan": "V5_1.4.6 Build 260709 Rel.27675n",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "defaultStatus": "unaffected",
                "product": "Tapo C120 v1",
                "vendor": "TP-Link Systems Inc.",
                "versions": [
                  {
                    "lessThan": "V1_1.9.4 Build 260813 Rel.79754n",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "source": "f23511db-6c3e-4e32-a477-6aa17d310630"
          }
        ],
        "cveTags": [],
        "descriptions": [
          {
            "lang": "en",
            "value": "Tapo C120 v1 and C200 V5\ncontain a vulnerability in the HTTPS onboarding scan function due to missing authentication.\nAfter initial setup, an unauthenticated attacker on the same local network can\ninvoke the scan action and retrieve nearby wireless access-point metadata,\nincluding SSIDs, BSSIDs, authentication and encryption modes, and\nsignal-strength information.\n\n\n\n\n\n\n\n\n\nSuccessful\nexploitation may disclose information about the wireless environment\nsurrounding the camera, allowing an attacker to learn elements of the local\nwireless topology."
          }
        ],
        "id": "CVE-2026-78577",
        "lastModified": "2026-10-01T20:36:38.330",
        "metrics": {
          "cvssMetricV40": [
            {
              "cvssData": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "ADJACENT",
                "availabilityRequirement": "NOT_DEFINED",
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "confidentialityRequirement": "NOT_DEFINED",
                "exploitMaturity": "NOT_DEFINED",
                "integrityRequirement": "NOT_DEFINED",
                "modifiedAttackComplexity": "NOT_DEFINED",
                "modifiedAttackRequirements": "NOT_DEFINED",
                "modifiedAttackVector": "NOT_DEFINED",
                "modifiedPrivilegesRequired": "NOT_DEFINED",
                "modifiedSubAvailabilityImpact": "NOT_DEFINED",
                "modifiedSubConfidentialityImpact": "NOT_DEFINED",
                "modifiedSubIntegrityImpact": "NOT_DEFINED",
                "modifiedUserInteraction": "NOT_DEFINED",
                "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
                "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
                "modifiedVulnIntegrityImpact": "NOT_DEFINED",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "LOW",
                "vulnIntegrityImpact": "NONE",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "source": "f23511db-6c3e-4e32-a477-6aa17d310630",
              "type": "Secondary"
            }
          ],
          "ssvcV203": [
            {
              "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "ssvcData": {
                "id": "CVE-2026-78577",
                "options": [
                  {
                    "exploitation": "none"
                  },
                  {
                    "automatable": "no"
                  },
                  {
                    "technicalImpact": "partial"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-10-01T18:08:50.711151Z",
                "version": "2.0.3"
              }
            }
          ]
        },
        "published": "2026-10-01T18:17:27.850",
        "references": [
          {
            "source": "f23511db-6c3e-4e32-a477-6aa17d310630",
            "url": "https://www.tp-link.com/en/support/download/tapo-c120/v1.26/#Firmware-Release-Notes"
          },
          {
            "source": "f23511db-6c3e-4e32-a477-6aa17d310630",
            "url": "https://www.tp-link.com/en/support/download/tapo-c200/v5/#Firmware-Release-Notes"
          },
          {
            "source": "f23511db-6c3e-4e32-a477-6aa17d310630",
            "url": "https://www.tp-link.com/us/support/download/tapo-c120/v1.26/#Firmware-Release-Notes"
          },
          {
            "source": "f23511db-6c3e-4e32-a477-6aa17d310630",
            "url": "https://www.tp-link.com/us/support/download/tapo-c200/v5/#Firmware-Release-Notes"
          },
          {
            "source": "f23511db-6c3e-4e32-a477-6aa17d310630",
            "url": "https://www.tp-link.com/us/support/faq/5321/"
          }
        ],
        "sourceIdentifier": "f23511db-6c3e-4e32-a477-6aa17d310630",
        "vulnStatus": "Deferred",
        "weaknesses": [
          {
            "description": [
              {
                "lang": "en",
                "value": "CWE-306"
              }
            ],
            "source": "f23511db-6c3e-4e32-a477-6aa17d310630",
            "type": "Secondary"
          }
        ]
      }
    },
    "vulnrichment": {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-78577",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-01T18:08:50.711151Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-01T18:08:54.790Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Tapo C200 v5",
              "vendor": "TP-Link Systems Inc.",
              "versions": [
                {
                  "lessThan": "V5_1.4.6 Build 260709 Rel.27675n",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "Tapo C120 v1",
              "vendor": "TP-Link Systems Inc.",
              "versions": [
                {
                  "lessThan": "V1_1.9.4 Build 260813 Rel.79754n",
                  "status": "affected",
                  "version": "0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Thai Do (Lio) and Khoi Tran (KayTii) from OPSWAT"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cp\u003eTapo C120 v1 and C200 V5\ncontain a vulnerability in the HTTPS onboarding scan function due to missing authentication.\nAfter initial setup, an unauthenticated attacker on the same local network can\ninvoke the scan action and retrieve nearby wireless access-point metadata,\nincluding SSIDs, BSSIDs, authentication and encryption modes, and\nsignal-strength information.\u003c/p\u003e\u003cp\u003e\n\n\u003c/p\u003e\u003cp\u003eSuccessful\nexploitation may disclose information about the wireless environment\nsurrounding the camera, allowing an attacker to learn elements of the local\nwireless topology.\u0026nbsp;\u003cb\u003e\u003c/b\u003e\u003c/p\u003e"
                }
              ],
              "value": "Tapo C120 v1 and C200 V5\ncontain a vulnerability in the HTTPS onboarding scan function due to missing authentication.\nAfter initial setup, an unauthenticated attacker on the same local network can\ninvoke the scan action and retrieve nearby wireless access-point metadata,\nincluding SSIDs, BSSIDs, authentication and encryption modes, and\nsignal-strength information.\n\n\n\n\n\n\n\n\n\nSuccessful\nexploitation may disclose information about the wireless environment\nsurrounding the camera, allowing an attacker to learn elements of the local\nwireless topology."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-1",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-1 Accessing Functionality Not Properly Constrained by ACLs"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "ADJACENT",
                "baseScore": 5.3,
                "baseSeverity": "MEDIUM",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "LOW",
                "vulnIntegrityImpact": "NONE",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-306",
                  "description": "CWE-306 Missing authentication for critical function",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-01T17:41:49.774Z",
            "orgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
            "shortName": "TPLink"
          },
          "references": [
            {
              "tags": [
                "patch"
              ],
              "url": "https://www.tp-link.com/us/support/download/tapo-c200/v5/#Firmware-Release-Notes"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://www.tp-link.com/en/support/download/tapo-c200/v5/#Firmware-Release-Notes"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://www.tp-link.com/us/support/download/tapo-c120/v1.26/#Firmware-Release-Notes"
            },
            {
              "tags": [
                "patch"
              ],
              "url": "https://www.tp-link.com/en/support/download/tapo-c120/v1.26/#Firmware-Release-Notes"
            },
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://www.tp-link.com/us/support/faq/5321/"
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Unauthenticated Onboarding Scan Information Disclosure in TP-Link Tapo C120 \u0026 C200",
          "x_generator": {
            "engine": "Vulnogram 1.0.5"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f23511db-6c3e-4e32-a477-6aa17d310630",
        "assignerShortName": "TPLink",
        "cveId": "CVE-2026-78577",
        "datePublished": "2026-10-01T17:41:49.774Z",
        "dateReserved": "2026-08-24T20:46:18.534Z",
        "dateUpdated": "2026-10-01T18:08:59.956Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }
  }
}



Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Forecast uses a logistic model when the trend is rising, or an exponential decay model when the trend is falling. Fitted via linearized least squares.

Sightings

Author Source Type Date Other

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or observed by the user.
  • Confirmed: The vulnerability has been validated from an analyst's perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
  • Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
  • Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
  • Not confirmed: The user expressed doubt about the validity of the vulnerability.
  • Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.

Loading…

Loading…

Loading…

Related by attack behaviour

Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.


Loading…