TP-LINK has disclosed three high‑severity vulnerabilities in its Tapo C325WB cameras, all affecting hardware version V2. The flaws could enable unauthenticated attackers on the adjacent network to manipulate live video streams or the camera’s settings. The firm has issued a patch, with firmware version V2_1.3.3 Build 260914, and users are urged to update immediately via the Tapo app.
The three defects are tracked as CVE-2026-105672 (Unauthenticated JSON API Authorization Bypass), CVE-2026-105674 (Predictable Media Stream Pre-Shared Key), and CVE-2026-105673 (Unauthenticated RTSP Tunnel Denial-of-Service). CVSSv4 scores place the first two at 8.7 and the third at 7.1.
The advisory notes that the JSON API bypass allows an attacker on the local network to bypass session verification by appending an onboarding-scoped object to a JSON request; the RTSP tunneling flaw can crash the streaming daemon; and the pre-shared key weakness makes the media stream vulnerable to hijack due to a time‑seeded pseudo‑random generator producing predictable keys. At present, there is no confirmed exploitation in the wild.
Exploitation status is described as not exploited to date. TP-Link recommends upgrading to V2_1.3.3 Build 260914 through the official Tapo mobile application and ensuring the local wireless network uses strong encryption to limit adjacent access.