CVE-2023-49515: TP-Link Tapo c200 Firmware

Medium severity, CVSS 4.6. EPSS: 0.4% chance of exploitation in the next 30 days.

Insecure Permissiosn vulnerability in TP Link TC70 and C200 WIFI Camera v.3 firmware v.1.3.4 and fixed in v.1.3.11 allows a physically proximate attacker to obtain sensitive information via a connection to the UART pin components.

Affected products

  • TP-Link Tapo c200 Firmware: version 1.1.22 only; version 1.3.4 only; version 1.3.9 only
  • TP-Link Tapo TC70 Firmware: version 1.1.22 only; version 1.3.4 only; version 1.3.9 only

Published 2024-01-17. Last modified 2026-06-17.