CameraRisk

TP-Link Tapo C200

cpe:2.3:*:tp-link:tapo_c200

Vendor
TP-Link
Device type
Not derivable from CPE
Published vulnerabilities
12
In CISA KEV
None
Affected versions recorded
28
Data last built
5 September 2026

Security summary

12 published vulnerabilities affect this product according to NVD.

Experimental risk indicator

Components are shown separately and deliberately not combined into a single number. Two of the six inputs below have no public source for any product on this site; a composite built without them would be a guess wearing a decimal point.

Known vulnerability count 12 bar scaled to 20
Highest published severity 9.8 CRITICAL
Confirmed exploitation no none listed in KEV
Exploitation probability EPSS 72.4% (highest)
Lifecycle status no source
Deployed exposure not measurable from public data

Published vulnerabilities

CVEPublishedCVSS SeverityEPSSFlags
CVE-2026-15316 2026-08-18 7.1 high 0.2% Vendor advisory
CVE-2026-15315 2026-08-18 8.7 high 0.3% Vendor advisory
CVE-2026-12760 2026-06-24 7.1 high 0.4% Vendor advisory
CVE-2026-1871 2026-06-02 7.1 high 0.3% Vendor advisory
CVE-2025-8065 2025-12-20 8.7 high 0.5% Vendor advisory
CVE-2025-14300 2025-12-20 8.7 high 0.4% Vendor advisory
CVE-2025-14299 2025-12-20 7.1 high 0.2% Vendor advisory
CVE-2023-49515 2024-01-17 4.6 medium 0.4% Exploit ref
CVE-2023-27098 2024-01-09 7.5 high 0.4% Exploit ref
CVE-2023-27126 2023-06-06 4.6 medium 0.4% Exploit ref
CVE-2021-4045 2022-03-10 9.8 critical 72.4% Exploit ref
CVE-2020-11445 2020-04-01 5.3 medium 1.8%

Affected versions

Version strings recorded by NVD against this product. These are the versions named in CPE match rules, not a complete firmware history — a version absent here has not been cleared, it has simply never been named in a CVE record.

1.0.12 · 1.0.13 · 1.0.17 · 1.0.5 · 1.1.22 · 1.1.4 · 1.1.8 · 1.2.2 · 1.2.3 · 1.3.1 · 1.3.11 · 1.3.13 · 1.3.14 · 1.3.15 · 1.3.3 · 1.3.4 · 1.3.5 · 1.3.7 · 1.3.9 · 1.4.1 · 1.4.2 · 1.4.4 · 3 · 5 · 5.0

Ranges: < 1.4.6 · <= 1.1.15 · <= 2020-02-09

What this page does not tell you

There is no public dataset of end-of-support dates, default credentials or shipped network services for this product, so those fields are absent rather than estimated. Whether any of these vulnerabilities is exploitable in your deployment depends on firmware version, configuration and network position — none of which is knowable from here.

For the vendor's own advisories, see TP-Link.

Other TP-Link products

Vulnerability records from the National Vulnerability Database, matched to this product by CPE. Exploitation status from CISA KEV 2026.09.04. Exploitation probability from FIRST EPSS, 2026-09-04. Product name derived mechanically from the CPE identifier. See methodology.