CVE-2026-105674: TP-Link Systems Inc Tapo c325wb v2
High severity, CVSS 8.7. EPSS: 0.2% chance of exploitation in the next 30 days.
TP-Link Tapo C325WB V2 generates the pre-shared key used by its local media streaming service with a time-seeded pseudo-random number generator, making the key predictable and recoverable. An unauthenticated attacker on the adjacent network can recover the key and authenticate to the media streaming service without valid user credentials. Successful exploitation may allow an unauthenticated adjacent-network attacker to access and take over live video and audio streams, compromising the confidentiality and integrity of camera media.
Affected products
- TP-Link Systems Inc Tapo c325wb v2: before V2_1.3.3 Build 260914 (fixed in V2_1.3.3 Build 260914)
Published 2026-10-08. Last modified 2026-10-09.