CVE-2026-78577 - Unauthenticated Onboarding Scan Information Disclosure in TP-Link Tapo C120 & C200
CVE ID :CVE-2026-78577
Published : Oct. 1, 2026, 6:17 p.m. | 56 minutes ago
Description :Tapo C120 v1 and C200 V5 contain a vulnerability in the HTTPS onboarding scan function due to missing authentication. After initial setup, an unauthenticated attacker on the same local network can invoke the scan action and retrieve nearby wireless access-point metadata, including SSIDs, BSSIDs, authentication and encryption modes, and signal-strength information. Successful exploitation may disclose information about the wireless environment surrounding the camera, allowing an attacker to learn elements of the local wireless topology.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Oct. 1, 2026, 6:17 p.m. | 56 minutes ago
Description :Tapo C120 v1 and C200 V5 contain a vulnerability in the HTTPS onboarding scan function due to missing authentication. After initial setup, an unauthenticated attacker on the same local network can invoke the scan action and retrieve nearby wireless access-point metadata, including SSIDs, BSSIDs, authentication and encryption modes, and signal-strength information. Successful exploitation may disclose information about the wireless environment surrounding the camera, allowing an attacker to learn elements of the local wireless topology.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...