Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-105672— Unauthenticated JSON API Authorization Bypass Vulnerability in TP-Link Tapo C325WB

Quick assessment

Affected
TP-Link Systems Inc. Tapo C325WB v2
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

TP-Link Tapo C325WB V2 在 TCP 443 端口的 HTTPS JSON API 分发模块中存在一个未认证的授权绕过漏洞。处于相邻网络中的攻击者可以通过在 JSON 请求中附加一个“初始设置作用域”的对象,来绕过会话验证,从而在未进行身份认证的情况下调用特权操作。 成功利用该漏洞可使未认证的相邻网络攻击者访问实时音视频流、修改设备设置,并获取敏感的设备信息或机密数据。

CVSS 8.7 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-105672

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Unauthenticated JSON API Authorization Bypass Vulnerability in TP-Link Tapo C325WB
Source: CVE Program / CVE List V5
Vulnerability Description
TP-Link Tapo C325WB V2 contains an unauthenticated authorization bypass vulnerability in the HTTPS JSON API dispatcher on TCP port 443. An attacker on the adjacent network can append an onboarding-scoped object to a JSON request to bypass session verification and invoke privileged actions without authentication.  Successful exploitation may allow an unauthenticated adjacent-network attacker to access live video and audio, modify device settings, and obtain sensitive device information or secrets.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
认证机制不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
TP-Link Systems Inc. Tapo C325WB v2 0 ~ V2_1.3.3 Build 260914 -

II. Public POCs for CVE-2026-105672

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-105672

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-105672 (1)

Vendor Pages for CVE-2026-105672 (1)

Same Patch Batch · TP-Link Systems Inc. · 2026-10-08 · 3 CVEs total

CVE-2026-105674 8.7 HIGH Predictable Media Stream Pre-Shared Key Vulnerability in TP-Link Tapo C325WB
CVE-2026-105673 7.1 HIGH Unauthenticated RTSP Tunnel Denial-of-Service Vulnerability in TP-Link Tapo C325WB

IV. Related Vulnerabilities

V. Comments for CVE-2026-105672

No comments yet


Leave a comment