Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-105674— Predictable Media Stream Pre-Shared Key Vulnerability in TP-Link Tapo C325WB

Quick assessment

Affected
TP-Link Systems Inc. Tapo C325WB v2
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

TP-Link Tapo C325WB V2 使用基于时间种子伪随机数生成器来生成其本地媒体流服务所使用的预共享密钥,导致该密钥具有可预测性且可被恢复。位于相邻网络中的未授权攻击者可以恢复该密钥,并在无需有效用户凭据的情况下对媒体流服务进行认证。 成功利用此漏洞可能使相邻网络中的未授权攻击者能够访问并接管实时视频和音频流,从而导致摄像头媒体的机密性和完整性遭到破坏。

CVSS 8.7 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-105674

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Predictable Media Stream Pre-Shared Key Vulnerability in TP-Link Tapo C325WB
Source: CVE Program / CVE List V5
Vulnerability Description
TP-Link Tapo C325WB V2 generates the pre-shared key used by its local media streaming service with a time-seeded pseudo-random number generator, making the key predictable and recoverable. An unauthenticated attacker on the adjacent network can recover the key and authenticate to the media streaming service without valid user credentials.  Successful exploitation may allow an unauthenticated adjacent-network attacker to access and take over live video and audio streams, compromising the confidentiality and integrity of camera media.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
使用不充分的随机数
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
TP-Link Systems Inc. Tapo C325WB v2 0 ~ V2_1.3.3 Build 260914 -

II. Public POCs for CVE-2026-105674

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-105674

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-105674 (1)

Vendor Pages for CVE-2026-105674 (1)

Same Patch Batch · TP-Link Systems Inc. · 2026-10-08 · 3 CVEs total

CVE-2026-105672 8.7 HIGH Unauthenticated JSON API Authorization Bypass Vulnerability in TP-Link Tapo C325WB
CVE-2026-105673 7.1 HIGH Unauthenticated RTSP Tunnel Denial-of-Service Vulnerability in TP-Link Tapo C325WB

IV. Related Vulnerabilities

V. Comments for CVE-2026-105674

No comments yet


Leave a comment