TL;DR
TP-Link disclosed three high-severity Tapo C325WB vulnerabilities affecting its smart security cameras. These flaws allow unauthenticated attackers on the adjacent network to bypass authorization, crash services, or recover predictable streaming keys. Users must upgrade their device firmware immediately to prevent unauthorized access to live video feeds.
- Product: TP-Link Systems Inc. Tapo C325WB v2
- Vulnerabilities: 3 flaws (CVE-2026-105672, CVE-2026-105673, CVE-2026-105674)
- Highest severity: 8.7 (High · CVSSv4)
- Worst impact: Unauthenticated JSON API Authorization Bypass in TP-Link Tapo C325WB
- Status: No confirmed exploitation yet; patches available
- Action: Update to V2_1.3.3 Build 260914 now
| CVE | CVSS (CVSSv4) | Type | Fixed in | Status |
|---|---|---|---|---|
| CVE-2026-105672 | 8.7 | Unauthenticated JSON API Authorization Bypass in TP-Link Tapo C325WB | V2_1.3.3 Build 260914 | Not exploited |
| CVE-2026-105674 | 8.7 | Predictable Media Stream Pre-Shared Key in TP-Link Tapo C325WB | V2_1.3.3 Build 260914 | Not exploited |
| CVE-2026-105673 | 7.1 | Unauthenticated RTSP Tunnel Denial-of-Service in TP-Link Tapo C325WB | V2_1.3.3 Build 260914 | Not exploited |
Running Infra, AppSec, and SOC teams? Tag CVE alerts by team automatically.
Try Team free for 14 daysWhy It Matters
Security cameras protect homes and businesses, making their integrity paramount. TP-Link Tapo devices serve millions of global customers, creating a massive attack surface for local network intruders. Unpatched Tapo C325WB vulnerabilities grant attackers direct access to private video and audio streams. Furthermore, adversaries can manipulate device settings and extract sensitive secrets. Compromised cameras severely undermine physical security and personal privacy.
How The Attack Works
Attackers exploit three distinct flaws to compromise the cameras. First, CVE-2026-105672 involves an unauthenticated JSON API authorization bypass. As TP-Link notes, “An attacker on the adjacent network can append an onboarding-scoped object to a JSON request to bypass session verification.” Second, CVE-2026-105673 causes a denial-of-service condition via crafted RTSP-over-HTTP tunneling requests, which crash the streaming daemon. Finally, CVE-2026-105674 arises from a predictable pre-shared key generated by a time-seeded pseudo-random number generator. According to the advisory, this makes the key “predictable and recoverable,” enabling unauthenticated attackers to hijack the media stream.
Exploitation Status
Currently, no active exploitation in the wild has been confirmed for these security flaws.
Affected Versions
These flaws specifically affect the Tapo C325WB hardware version V2.
Patch And Mitigation Steps
TP-Link released firmware version V2_1.3.3 Build 260914 to resolve these issues. You must install this update through the official Tapo mobile application. Finally, ensure your local wireless network uses strong encryption to prevent adjacent attackers from reaching the camera.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!