PT-2026-108282 · Tp Link Systems · Tapo C325Wb V2
CVE-2026-105672
·
Published
2026-10-08
·
Updated
2026-10-08
CVSS v4.0
8.7
High
| Vector | AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
TP-Link Tapo
C325WB V2 contains an unauthenticated authorization bypass vulnerability in the
HTTPS JSON API dispatcher on TCP port 443. An attacker on the adjacent network
can append an onboarding-scoped object to a JSON request to bypass session
verification and invoke privileged actions without authentication.
Successful
exploitation may allow an unauthenticated adjacent-network attacker to access
live video and audio, modify device settings, and obtain sensitive device
information or secrets.
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tapo C325Wb V2