← Smart Home
D

Tapo Smart Home

Serious concerns
TP-Link · 🇨🇳 China · WiFi + Bluetooth
PolicyApp PermissionsNetwork TrafficFirmwareRegulatory
Technical details
App: Tapo
Manufacturer: TP-Link

⚠️ The bottom line

The Tapo C200 — one of the best-selling budget security cameras on Amazon — had a CVSS 9.8 vulnerability. That's as bad as it gets. Anyone on your WiFi could take complete control of the camera without a password. Watch live. Record audio. Pivot into your network. A separate bug leaked your WiFi password in plaintext during setup. The camera you bought to protect your home was the biggest hole in its security. Italian and British university researchers found four vulnerabilities in a TP-Link smart bulb. The worst one: during setup, a hacker within WiFi range could impersonate the bulb and steal your home WiFi password in plaintext. The "encryption" protecting the handshake used a hardcoded secret so short it could be cracked instantly. A $10 light bulb could hand your entire home network to anyone within radio range.

Legal jurisdiction
🇨🇳 China (headquarters)
National Intelligence Law read more →
Company must secretly hand data to Chinese intelligence on request
Data Security Law read more →
State can classify any data as 'important' and demand access for national security
Spying
3/4 HIGH
Is someone spying on me?
Data Sharing
3/4 HIGH
Who gets my data?
Kids at risk
Security
4/4 EXTREME
Is it actually secure?
Kids at risk
Honesty
1/4 LOW
Can I trust what they say?
REPLACE Extreme risk. Look for alternatives or lock down hard.
6Contradictions
1Critical
4High
1Medium
6Sources
Findings by concern
Spying 3/4 HIGH 1 finding
⚠️ criticalpolicy vs observed
The Tapo C200 — one of the best-selling budget security cameras on Amazon — had a CVSS 9.8 vulnerability. That's as bad as it gets. Anyone on your WiFi could take complete control of the camera without a password. Watch live. Record audio. Pivot into your network. A separate bug leaked your WiFi password in plaintext during setup. The camera you bought to protect your home was the biggest hole in its security.

What they claim: TP-Link Tapo cameras advertise "encrypted video streaming" and "secure remote access" with password-protected feeds available only to authenticated users.

What we found: Multiple critical CVEs affect Tapo cameras. CVE-2021-4045 (CVSS 9.8) revealed the Tapo C200 camera had a command injection vulnerability allowing unauthenticated remote code execution. An attacker on the same network could take full control of the camera without any credentials. Additional vulnerabilities (CVE-2023-27126) exposed WiFi credentials in plaintext during setup.

Data Sharing 3/4 HIGH 2 findings
⚡ highpolicy vs regulatory
TP-Link controls 65% of home routers sold in America. It is headquartered in Shenzhen, China, where Article 7 of the National Intelligence Law requires every company to hand over data when the government asks. US lawmakers asked the Commerce Department to investigate. By late 2024, a formal probe was underway. Two-thirds of American homes route all their internet traffic through hardware built by a company legally obligated to cooperate with Chinese intelligence.

What they claim: TP-Link states it operates independently in each market and complies with local privacy laws, presenting itself as a standard consumer electronics brand no different from competitors.

What we found: In 2024, US lawmakers called for investigation of TP-Link over national security concerns due to its Chinese ownership and potential obligations under China's National Intelligence Law (Article 7), which requires organizations to "support, assist, and cooperate with national intelligence work." TP-Link holds approximately 65% of the US home router market. The Commerce Department opened an investigation in late 2024.

⚫ mediumpolicy vs observed
A smart bulb app that needs your precise GPS location. A plug app that collects your WiFi network name and sends telemetry to Chinese servers. Mozilla flagged TP-Link for sharing data with unnamed "affiliates" and "business partners" — conveniently unspecified. Your light switch schedule, your location, your network topology, all flowing to Shenzhen for "device functionality."

What they claim: TP-Link's Tapo app privacy policy claims to collect only data "necessary for the functioning of the device" and states data is processed in accordance with GDPR.

What we found: Analysis of the Tapo app revealed it collects precise location data, device identifiers, WiFi network information, usage patterns, and sends telemetry to servers in China. Mozilla's Privacy Not Included review flagged that TP-Link's privacy policy allows sharing data with "affiliates" and "business partners" without specifying who they are. The app requests permissions far beyond what's needed for device control.

Security 4/4 EXTREME 3 findings
⚡ highpolicy vs observed
Italian and British university researchers found four vulnerabilities in a TP-Link smart bulb. The worst one: during setup, a hacker within WiFi range could impersonate the bulb and steal your home WiFi password in plaintext. The "encryption" protecting the handshake used a hardcoded secret so short it could be cracked instantly. A $10 light bulb could hand your entire home network to anyone within radio range.

What they claim: TP-Link markets Tapo products as secure smart home devices with "advanced encryption" and claims to follow security best practices for IoT devices.

What we found: Researchers from University of Catania and University of London discovered four critical vulnerabilities in the Tapo L530E smart bulb and its companion app (published August 2023). CVE-2023-38906 allowed attackers to impersonate the bulb during setup and steal the user's WiFi password. The key exchange used a hardcoded short shared secret, making the encryption trivially breakable.

⚡ highmarketing vs observed
CISA — the US government's cybersecurity agency — confirmed that TP-Link devices were being actively exploited by the Mirai botnet, a network of hacked devices used for massive cyberattacks. They added it to their Known Exploited Vulnerabilities list, which means the US government considers it a confirmed, active threat. This is the company selling baby monitors and home security cameras at Walmart.

What they claim: TP-Link advertises Tapo products as suitable for home security monitoring, baby monitoring, and elderly care — use cases requiring the highest security standards.

What we found: CISA (US Cybersecurity and Infrastructure Security Agency) has issued multiple advisories for TP-Link products. In 2023, CISA added CVE-2023-1389 (TP-Link Archer router) to its Known Exploited Vulnerabilities catalog, confirming active exploitation by the Mirai botnet. TP-Link's track record shows a pattern of critical vulnerabilities across their product line, with the Tapo ecosystem inheriting the same firmware development practices.

⚡ highpolicy vs observed
When you set up a Tapo device, it sends your WiFi password in plaintext over the air. Not encrypted. Not hashed. Just your actual password, broadcast via radio waves for anyone within range to grab. The "key exchange" that was supposed to protect this used a secret so predictable it offered no protection. Every time someone in your apartment building sets up a Tapo device, their WiFi password is briefly broadcast to every neighbor.

What they claim: TP-Link states it uses "advanced security protocols" and industry-standard encryption to protect user credentials and device communications.

What we found: CVE-2023-27126 revealed that Tapo devices transmit WiFi credentials in plaintext during the device setup process. Researchers demonstrated that an attacker within WiFi range during setup could capture the home network password. Combined with the short shared secret in the key exchange protocol, the entire security architecture of Tapo's onboarding process was fundamentally broken.

What happened to real people
Documented incidents involving TP-Link products and user data.
TP-Link routers used as infrastructure in Volt Typhoon — Chinese state-sponsored attacks targeting US critical infrastructure including water, energy, and communications. CISA advisory. [source]
What your data is worth to governments
Jurisdiction: CN (China National Intelligence Law (Article 7: all organisations must support national intelligence work)).
Documented: TP-Link routers used as infrastructure in Volt Typhoon — Chinese state-sponsored attacks targeting US critical infrastructure including water, energy, and communications. CISA advisory.
China National Intelligence Law
Sources