do not adequately protect login challenge data or sanitize
attacker-controlled input processed by the MacTool handler. An unauthenticated
attacker on the same local network can replay login challenge data to obtain an
administrative session, enable a privileged service that becomes accessible
after a reboot, and submit crafted input to execute arbitrary commands within
the device management process.
Successful
exploitation may allow arbitrary command execution on the camera and compromise
the confidentiality, integrity, and availability of the affected device.
Exploitation requires access from the same local network, replay of the login
challenge data, activation of the privileged service, and a device reboot.
Project Subscriptions
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 01 Oct 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tp-link
Tp-link tapo C120 V1 Tp-link tapo C200 V5 |
|
| Vendors & Products |
Tp-link
Tp-link tapo C120 V1 Tp-link tapo C200 V5 |
Thu, 01 Oct 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 01 Oct 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Tapo C120 v1 and C200 V5 do not adequately protect login challenge data or sanitize attacker-controlled input processed by the MacTool handler. An unauthenticated attacker on the same local network can replay login challenge data to obtain an administrative session, enable a privileged service that becomes accessible after a reboot, and submit crafted input to execute arbitrary commands within the device management process. Successful exploitation may allow arbitrary command execution on the camera and compromise the confidentiality, integrity, and availability of the affected device. Exploitation requires access from the same local network, replay of the login challenge data, activation of the privileged service, and a device reboot. | |
| Title | Unauthenticated Remote Code Execution via MacTool Command Injection in TP-Link Tapo C120 & C200 | |
| Weaknesses | CWE-287 | |
| References |
|
|
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: TPLink
Published:
Updated: 2026-10-01T18:08:05.015Z
Reserved: 2026-09-28T23:02:41.717Z
Link: CVE-2026-102369
Updated: 2026-10-01T18:08:00.590Z
Status : Deferred
Published: 2026-10-01T18:17:12.400
Modified: 2026-10-01T20:36:38.330
Link: CVE-2026-102369
No data.
OpenCVE Enrichment
Updated: 2026-10-01T19:33:16Z