All CVEs
Vulnerability intelligence

CVE-2026-105672

TP-Link Systems Inc. Tapo C325WB v2 CWE-287

TP-Link Tapo C325WB V2 contains an unauthenticated authorization bypass vulnerability in the HTTPS JSON API dispatcher on TCP port An attacker on the adjacent network can append an onboarding-scoped object to a JSON request to bypass session verification and invoke privileged actions without authentication. Successful exploitation may allow an unauthenticated adjacent-network attacker to access live video and audio, modify device settings, and obtain sensitive device information or secrets.

CVSS Score
8.7
High
EPSS — Exploit Probability
—
Awaiting FIRST.org data · checked 2026-10-09
Exploitation
Not in CISA KEV
KEV does not include every exploited vulnerability
Remediation
Patch available
Vendor fix published
NVD entry Vendor patch PoC / advisory

1 article across 1 outlet · first covered Oct 9, 2026 · latest Oct 9, 2026

Coverage timeline

Related CVEs — TP-Link Systems Inc.