Vulnerability intelligence
CVE-2026-105674
TP-Link Tapo C325WB V2 generates the pre-shared key used by its local media streaming service with a time-seeded pseudo-random number generator, making the key predictable and recoverable. An unauthenticated attacker on the adjacent network can recover the key and authenticate to the media streaming service without valid user credentials. Successful exploitation may allow an unauthenticated adjacent-network attacker to access and take over live video and audio streams, compromising the confidentiality and integrity of camera media.
CVSS Score
8.7
High
EPSS — Exploit Probability
—
Awaiting FIRST.org data · checked 2026-10-09
Exploitation
Not in CISA KEV
KEV does not include every exploited vulnerability
Remediation
Patch available
Vendor fix published
1 article across 1 outlet · first covered Oct 9, 2026 · latest Oct 9, 2026
Coverage timeline
-
TP-Link Patches Tapo Cameras Flaws That Could Let Attackers Hijack Video Streamssecurityonline.info · Oct 9, 2026