CVE-2026-78578: Unauthenticated do Method Onboarding Connect Allows Wi‑Fi Reconfiguration Denial of Service Vulnerability in TP-Link Tapo C120 & C200
Tapo C120 v1 and C200 v5 do not enforce authentication for do method HTTPS onboarding connect actions after initial setup. An unauthenticated adjacent attacker can submit unauthorized wireless configuration parameters, causing the camera to attempt connection to a different network.
Successful exploitation disconnects the camera from its intended wireless network, making it unreachable on its management address, resulting in a denial-of-service condition.
Affected Software
Event History
Frequently Asked Questions
Which devices and configurations are exposed?
TP-Link Tapo C120 v1 and Tapo C200 v5 are affected after their initial setup. The issue involves HTTPS onboarding connect actions that do not enforce authentication.
What does an attacker need to exploit this issue?
An attacker must be adjacent to the affected camera and able to submit unauthorized wireless configuration parameters through the unauthenticated onboarding connect action. No authentication is required for that action.
What is the practical impact of successful exploitation?
The attacker can cause the camera to attempt to join a different wireless network. This disconnects it from its intended network and makes it unreachable at its management address, creating a denial-of-service condition.