Impact
Tapo C200 v5 contains an improper authentication failure in the login verification module. An attacker located on the local network can exploit weaknesses in the challenge parameter validation of the device_confirm endpoint to obtain administrative session tokens. Once authenticated, the attacker can execute privileged management actions, potentially modify device settings, and cause temporary service disruption, resulting in a denial‑of‑service condition.
Affected Systems
TP‑Link Systems Inc. – Tapo C200 v5 firmware version 5 is vulnerable; no other models or firmware versions are listed as affected.
Risk and Exploitability
The vulnerability has a CVSS score of 8.7, indicating high severity. EPSS is not available, and the vulnerability is not listed in CISA’s KEV catalog. The most likely attack vector is a local network attacker, as the flaw requires the attacker to be able to reach the device’s device_confirm interface. Successful exploitation grants administrative privileges, enabling the attacker to perform arbitrary management actions and possibly disrupt device services.
OpenCVE Enrichment