The Tapo C200 — one of the best-selling budget security cameras on Amazon — had a CVSS 9.8 vulnerability. That's as bad as it gets. Anyone on your WiFi could take complete control of the camera without a password. Watch live. Record audio. Pivot into your network. A separate bug leaked your WiFi password in plaintext during setup. The camera you bought to protect your home was the biggest hole in its security.
critical
CISA — the US government's cybersecurity agency — confirmed that TP-Link devices were being actively exploited by the Mirai botnet, a network of hacked devices used for massive cyberattacks. They added it to their Known Exploited Vulnerabilities list, which means the US government considers it a confirmed, active threat. This is the company selling baby monitors and home security cameras at Walmart.
critical
When you set up a Tapo device, it sends your WiFi password in plaintext over the air. Not encrypted. Not hashed. Just your actual password, broadcast via radio waves for anyone within range to grab. The "key exchange" that was supposed to protect this used a secret so predictable it offered no protection. Every time someone in your apartment building sets up a Tapo device, their WiFi password is briefly broadcast to every neighbor.
The Tapo app tracks your precise location even when you're not using it, and the camera itself broadcasts details about every WiFi network around it to anyone who asks. Together, this means both your phone's location and your camera's exact physical position in your home can be tracked without your knowledge.
high
TP-Link's privacy policy mentions collecting your location and device info for 'analytics,' but the app also secretly tracks your advertising identity to connect your camera usage with your browsing habits and ad profile. This advertising tracking is never mentioned in their privacy claims.
high
Your Tapo camera has a microphone that is always ready to listen, and the app can activate it in the background even after your phone restarts. Past security flaws allowed hackers to remotely turn on this microphone and listen to conversations inside your home — and there's no light or indicator to warn you when the microphone is recording.
This camera is designed for outdoors with a massive viewing range — it will inevitably record your neighbours, delivery drivers, and anyone walking past your home in crystal-clear 2K with AI that identifies them as people. But TP-Link's privacy policy says nothing about protecting those people's privacy. Everyone captured on your camera becomes part of TP-Link's data ecosystem without their knowledge or consent.
high
TP-Link says your camera footage is encrypted and secure, but security researchers found that the encryption keys are identical on every camera of the same model. Anyone on your WiFi network could potentially decrypt your video streams. This is like a lock manufacturer using the same key for every lock they sell.
high
TP-Link says they care about your privacy, but their app tracks your advertising ID, your location in the background, and sends data to Google Analytics. A security camera app has no reason to track your ad preferences or know your phone's unique identifiers — these permissions exist to profile you, not to protect your home.
TP-Link says your data goes to the US, Ireland, and Singapore — but never mentions China. Yet the company is headquartered in Hong Kong, the router hardware is designed and tested in Guangzhou, China, and the US government is considering banning TP-Link over national security concerns about Chinese government ties. The privacy policy is silent about where your data actually originates and who at the parent company can access it.
high
TP-Link presents HomeShield as an optional security subscription you can choose to enable. But the HomeShield code actually runs on your router whether you activate it or not — and it has a critical security hole that lets hackers take over your router through that always-running code. A similar TP-Link router was caught sending over 80,000 requests per day to a security company's servers even when the user never turned that feature on.
high
The app for your Wi-Fi router asks for permission to use your phone's camera, know your exact location, read your files, and draw over other apps on your screen. A router app needs none of these things to manage your home network. Once you grant these permissions for initial setup, the app keeps them forever.
TP-Link promises to strictly protect your data security, but their camera and app have had a chain of serious security holes — from password leaks in the app to complete camera takeover vulnerabilities. TP-Link acknowledged these but expects you to manually update your camera and app to stay safe.
high
TP-Link says they care about your privacy and security, but their app includes advertising tracking tools and requests permission to track your location even when you are not using it. The privacy page does not mention these advertising features.
high
The Tapo app asks for 41 permissions on your phone, including the ability to read your phone number, track your location in the background, access your phone's camera, draw over other apps, and manage phone calls. Most of these have nothing to do with running a security camera, and the privacy policy doesn't explain why they're needed.
TP-Link says your Deco router only tracks your browsing if you turn on Parental Controls. But users discovered the router secretly looks up popular websites like Netflix and Amazon on its own — even when nobody is using the internet. This means your router may be monitoring what sites your household visits without your knowledge or consent.
high
TP-Link claims your Deco router only sends a small amount of data to their servers. But the router constantly talks to at least five different TP-Link cloud servers and makes hundreds of time-check requests every few minutes. You cannot manage your own router without going through TP-Link's cloud — they see everything.
high
The app for your Wi-Fi router asks for permission to use your phone's camera. Your router doesn't have a camera and doesn't need one — so why does the app need camera access? It also asks to draw over other apps, which has nothing to do with managing your Wi-Fi.
TP-Link carefully words their privacy policy to say they do not use your personal info for targeted ads. But they never actually promise not to sell your data. Their app includes analytics trackers that monitor your behavior. The specific wording is a common legal technique that sounds protective but actually permits selling your data to other companies.
high
TP-Link sells a "security" feature called HomeCare that scans ALL internet traffic from every device in your home. But multiple US government agencies are investigating whether TP-Link could be forced by Chinese law to hand over exactly this kind of data to the Chinese government. Your router's "security" feature is also a surveillance capability — and the US government considers this a national security threat.
high
The TP-Link Tether app asks for permission to access your location, read your files, and draw over other apps — far more than what's needed to manage a router. Combined with the router itself sending data to 9 different cloud servers across three continents, you are being tracked from two directions: through your phone app AND through your router.
The app that controls your WiFi router asks for permission to use your phone camera, read your files, and access your precise location — none of which are needed to manage a WiFi network.
high
Your router secretly sends your browsing data (every website you visit) to a company called NortonLifeLock for "security scanning." This is buried in a separate privacy policy that most users never see.
high
Hackers backed by the Chinese government have turned thousands of TP-Link routers into a spy network. The U.S. government is so concerned it may ban the company entirely. Meanwhile, multiple security holes remain in the same router firmware.
Your smart plug stores your Wi-Fi password — it needs it to connect to your network. Security researchers proved that attackers can extract that password from the plug due to a protocol flaw. TP-Link's privacy policy says nothing about this risk. If someone exploits this, they get access to your entire home network.
high
TP-Link promotes AES-128 encryption as bank-grade security on their marketing page. Independent researchers found that this exact encryption implementation is the weakness that lets attackers intercept your data. They are advertising the vulnerability as a feature.
high
TP-Link claims your data is protected by TLS 1.2 encryption during transmission. Researchers found the smart plug communicates with your phone without any HTTPS encryption at all. Anyone on your Wi-Fi network could intercept commands and data between your phone and plug.
The smart plug tracks exactly how much electricity each of your connected devices uses and when. While marketed as a tool for you to save money, the privacy policy reveals this detailed power usage data — which can reveal your daily routines, what appliances you own, and when you're home — can be shared with a third-party energy company called OhmConnect, along with your account login information.
high
The Kasa app asks for permission to record audio through your phone's microphone, but the KP125 is just a plug that goes in your wall socket — it has no microphone or speaker. There is no legitimate reason a smart plug app needs to listen through your phone's microphone.
high
The app constantly tracks your phone's precise GPS location in the background — even when you're not using it — for a device that's permanently plugged into your wall. They say this is for automations that trigger when you leave home, but it means TP-Link can build a detailed map of everywhere you go, all day long, just because you bought a smart plug.
When you set up this smart bulb, it creates a temporary Wi-Fi network. Researchers proved that a nearby attacker can pretend to be your bulb during setup and steal your home Wi-Fi password, your Wi-Fi network name, and your TP-Link account login credentials — all because you wanted to connect a light bulb.
high
To control a light bulb that just turns on and off, TP-Link's app demands access to your camera, microphone, precise GPS location (even in the background), and phone information. A light bulb does not need to know where you are, what you look like, or what you sound like.
high
TP-Link admitted to three security flaws in their smart bulb but quietly left out the most serious one — a flaw that lets attackers replay commands to control your devices. They then told customers it's their fault if they don't update, while not fully disclosing what they need to update against.
TP-Link makes 65% of the routers Americans buy. The US government is investigating whether to ban them. Commerce, Defense, and Justice departments — all three probing one router company. TP-Link is headquartered in Shenzhen, China, subject to China's National Intelligence Law. Your router sees every device on your network, every website you visit, every connection you make. Two-thirds of American homes chose to put a Chinese government-obligated device between their entire digital life and the internet. The device that sees everything in your home is made by a company legally required to show everything to Beijing.
high
TP-Link routers have been recruited into botnets. The Mirai botnet exploited a command injection vulnerability in the Archer AX21 — one of the best-selling routers in America — to turn home routers into weapons for DDoS attacks. CISA flagged it as actively exploited. Researchers found hardcoded credentials, default admin passwords, and firmware updates that don't verify who sent them. Some models phone home to Chinese servers even after factory reset. Your router — the device that controls your entire home network — with hardcoded passwords and unverified firmware updates.
high
The app that manages your router sends your home network data to Google Analytics and Facebook. Every device name, every MAC address, when each device connects, how much bandwidth it uses. The TP-Link Tether app — your router management tool — contains advertising SDKs. Your home network topology, shared with ad companies through the app you use to manage your security. The app meant to protect your network is the app that leaks it.