TP-Link Tapo C325WB V2 使用基于时间种子伪随机数生成器来生成其本地媒体流服务所使用的预共享密钥,导致该密钥具有可预测性且可被恢复。位于相邻网络中的未授权攻击者可以恢复该密钥,并在无需有效用户凭据的情况下对媒体流服务进行认证。 成功利用此漏洞可能使相邻网络中的未授权攻击者能够访问并接管实时视频和音频流,从而导致摄像头媒体的机密性和完整性遭到破坏。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| TP-Link Systems Inc. | Tapo C325WB v2 | 0 ~ V2_1.3.3 Build 260914 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-105672 | 8.7 HIGH | Unauthenticated JSON API Authorization Bypass Vulnerability in TP-Link Tapo C325WB |
| CVE-2026-105673 | 7.1 HIGH | Unauthenticated RTSP Tunnel Denial-of-Service Vulnerability in TP-Link Tapo C325WB |
No comments yet