CVE-2025-1099: TP-Link Tapo c500 v1 Wi-Fi Camera

High severity, CVSS 7.0. EPSS: 0.3% chance of exploitation in the next 30 days.

This vulnerability exists in Tapo C500 Wi-Fi camera due to hard-coded RSA private key embedded within the device firmware. An attacker with physical access could exploit this vulnerability to obtain cryptographic private keys which can then be used to perform impersonation, data decryption and man in the middle attacks on the targeted device.

Affected products

  • TP-Link Tapo c500 v1 Wi-Fi Camera: up to and including 1.1.4
  • TP-Link Tapo c500 v2 Wi-Fi Camera: up to and including 1.0.2

Published 2025-02-10. Last modified 2026-06-17.