Vulnerability in TP-Link Tapo C325WB V2 Affects Media Streaming Security
CVE-2026-105674

8.7HIGH

Key Information:

Vendor
CVE Published:
8 October 2026

What is CVE-2026-105674?

The TP-Link Tapo C325WB V2 suffers from a vulnerability that generates its pre-shared key using a time-seeded pseudo-random number generator. This flaw renders the key predictable and easily recoverable by an unauthenticated attacker on the adjacent network, allowing unauthorized access to live video and audio streams. Such exploitation compromises both the confidentiality and integrity of the media being streamed, necessitating immediate attention to the product's security measures.

Affected Version(s)

Tapo C325WB v2 0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Andrey Charikov, Check Point Research
.