CVE-2026-105672: TP-Link Systems Inc Tapo c325wb v2
High severity, CVSS 8.7. EPSS: 0.2% chance of exploitation in the next 30 days.
TP-Link Tapo C325WB V2 contains an unauthenticated authorization bypass vulnerability in the HTTPS JSON API dispatcher on TCP port 443. An attacker on the adjacent network can append an onboarding-scoped object to a JSON request to bypass session verification and invoke privileged actions without authentication. Successful exploitation may allow an unauthenticated adjacent-network attacker to access live video and audio, modify device settings, and obtain sensitive device information or secrets.
Affected products
- TP-Link Systems Inc Tapo c325wb v2: before V2_1.3.3 Build 260914 (fixed in V2_1.3.3 Build 260914)
Published 2026-10-08. Last modified 2026-10-09.