CVE-2023-27126: TP-Link Tapo c200 Firmware

Medium severity, CVSS 4.6. EPSS: 0.4% chance of exploitation in the next 30 days.

The AES Key-IV pair used by the TP-Link TAPO C200 camera V3 (EU) on firmware version 1.1.22 Build 220725 is reused across all cameras. An attacker with physical access to a camera is able to extract and decrypt sensitive data containing the Wifi password and the TP-LINK account credential of the victim.

Affected products

  • TP-Link Tapo c200 Firmware: version 1.2.2 only

Published 2023-06-06. Last modified 2026-07-09.