do not adequately protect login challenge data or sanitize
attacker-controlled input processed by the MacTool handler. An unauthenticated
attacker on the same local network can replay login challenge data to obtain an
administrative session, enable a privileged service that becomes accessible
after a reboot, and submit crafted input to execute arbitrary commands within
the device management process.
Successful
exploitation may allow arbitrary command execution on the camera and compromise
the confidentiality, integrity, and availability of the affected device.
Exploitation requires access from the same local network, replay of the login
challenge data, activation of the privileged service, and a device reboot.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 01 Oct 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Tapo C120 v1 and C200 V5 do not adequately protect login challenge data or sanitize attacker-controlled input processed by the MacTool handler. An unauthenticated attacker on the same local network can replay login challenge data to obtain an administrative session, enable a privileged service that becomes accessible after a reboot, and submit crafted input to execute arbitrary commands within the device management process. Successful exploitation may allow arbitrary command execution on the camera and compromise the confidentiality, integrity, and availability of the affected device. Exploitation requires access from the same local network, replay of the login challenge data, activation of the privileged service, and a device reboot. | |
| Title | Unauthenticated Remote Code Execution via MacTool Command Injection in TP-Link Tapo C120 & C200 | |
| Weaknesses | CWE-287 | |
| References |
|
|
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: TPLink
Published:
Updated: 2026-10-01T18:08:05.015Z
Reserved: 2026-09-28T23:02:41.717Z
Link: CVE-2026-102369
No data.
Status : Received
Published: 2026-10-01T18:17:12.400
Modified: 2026-10-01T18:17:12.400
Link: CVE-2026-102369
No data.
OpenCVE Enrichment
No data.
-
CWE-287
Improper Authentication