TL;DR
TP-Link published four security advisories on October 1, 2026, covering seven TP-Link vulnerabilities. The worst, CVE-2026-102369, scores 8.7 on CVSS 4.0 and lets a local attacker run commands on Tapo cameras. Every flaw now has a firmware fix.
- Total: 7 CVEs
- Severity: 6 High · 1 Medium
- Actively exploited: None confirmed
- Highest severity: 8.7 (High · CVSSv4) — CVE-2026-102369
- Action: Apply the latest security updates now
Tired of noisy CVE feeds? Set your own EPSS/CVSS alert threshold.
Try free for 14 daysNotable CVEs
| CVE | CVSS (CVSSv4) | Type | Fixed in | Status |
|---|---|---|---|---|
| CVE-2026-102369 | 8.7 | Unauthenticated Remote Code Execution via MacTool Command Injection in TP-Link Tapo C120 & C200 | V5_1.4.6 Build 260709 Rel.27675n, V1_1.9.4 Build 260813 Rel.79754n | Not exploited |
| CVE-2026-102294 | 8.5 | Authenticated OS Command Injection in TL-WR841N IPv6 WAN Configuration | 4.19 Build 260821 (EN), 4.19 Build 260820 (US) | Not exploited |
| CVE-2026-84682 | 7.7 | TDDPv2 setProductVer Command Injection in Archer AX90 | 1.1.4 Build 20260927 | Not exploited |
| CVE-2026-8618 | 7.7 | Pre-Authentication Stack-based Buffer Overflow Remote Code Execution in TDDPv2 Subtype 0x91 on Deco M9 Plus | 1.9.2 Build 20260818 | Not exploited |
| CVE-2026-9032 | 7.1 | Unauthenticated Onboarding Connect NULL Pointer Dereference Denial of Service in TP-Link Tapo C120 & C200 | V5_1.4.6 Build 260709 Rel.27675n, V1_1.9.4 Build 260813 Rel.79754n | Not exploited |
| CVE-2026-78578 | 7.1 | Unauthenticated do Method Onboarding Connect Allows Wi‑Fi Reconfiguration Denial of Service in TP-Link Tapo C120 & C200 | V5_1.4.6 Build 260709 Rel.27675n, V1_1.9.4 Build 260813 Rel.79754n | Not exploited |
| CVE-2026-78577 | 5.3 | Unauthenticated Onboarding Scan Information Disclosure in TP-Link Tapo C120 & C200 | V5_1.4.6 Build 260709 Rel.27675n, V1_1.9.4 Build 260813 Rel.79754n | Not exploited |
Why It Matters
These TP-Link vulnerabilities all require access to the local network first. However, that bar is low on shared or poorly secured Wi-Fi. Five of the seven flaws need no login at all. Two of them allow full command execution, and one runs as root.
TP-Link’s advisories do not report active exploitation. Likewise, no public proof-of-concept has been confirmed. TP-Link does not publish install counts for the affected models.
The Tapo C200 has drawn scrutiny before. In August, TP-Link patched separate C200 flaws reported by OPSWAT researchers, according to Cybernews.
How the Attacks Work
Tapo C120 and C200 Cameras
The Tapo camera vulnerabilities form the largest group. CVE-2026-102369 pairs weak protection of login challenge data with poor input sanitization in a MacTool handler. As a result, a local attacker could replay login data and run commands on the camera.
Three more flaws hit the onboarding service. CVE-2026-78578 lets an attacker push unauthorized Wi-Fi settings and knock the camera off its network. CVE-2026-9032, a NULL pointer dereference, crashes the HTTPS service. Meanwhile, CVE-2026-78577 leaks nearby access point data, including SSIDs and encryption modes.
Archer AX90 and Deco M9 Plus
Both flaws sit in TP-Link’s TDDPv2 service. On the Archer AX90, TP-Link warns that an attacker “can exploit the setProductVer command handler to execute arbitrary operating system commands as root during device boot.” On the Deco M9 Plus, CVE-2026-8618 is a stack-based buffer overflow in the subtype 0x91 handler. It can crash the device or allow code execution during setup.
TL-WR841N
CVE-2026-102294 affects the IPv6 WAN settings. The router feeds a crafted IPv6 Gateway value into a system command. Consequently, an authenticated administrator could run arbitrary OS commands.
Affected Versions
- Tapo C120 V1 and Tapo C200 V5: CVE-2026-102369, CVE-2026-9032, CVE-2026-78577, CVE-2026-78578
- Archer AX90 V1: CVE-2026-84682
- Deco M9 Plus V2: CVE-2026-8618
- TL-WR841N V14: CVE-2026-102294
Patches and Mitigation
TP-Link urges users to install these firmware builds:
- Tapo C120 V1: 1.9.4 Build 260813, and Tapo C200 V5: 1.4.6 Build 260709 (see the Tapo C120 and C200 advisory)
- Archer AX90 V1: 1.1.4 Build 20260927 (see the Archer AX90 command injection advisory)
- Deco M9 Plus V2: 1.9.2 Build 20260818 (see the Deco M9 Plus buffer overflow advisory)
- TL-WR841N V14: 4.19 Build 260821 (EN) or Build 260820 (US) (see the TL-WR841N IPv6 advisory)
Beyond patching, owners can limit who joins the local network. A separate guest network for visitors also cuts exposure to these TP-Link vulnerabilities.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!