CVE-2026-105674 PUBLISHED

Predictable Media Stream Pre-Shared Key Vulnerability in TP-Link Tapo C325WB

Assigner: TPLink
Reserved: 05.10.2026 Published: 08.10.2026 Updated: 08.10.2026

TP-Link Tapo C325WB V2 generates the pre-shared key used by its local media streaming service with a time-seeded pseudo-random number generator, making the key predictable and recoverable. An unauthenticated attacker on the adjacent network can recover the key and authenticate to the media streaming service without valid user credentials. 

Successful exploitation may allow an unauthenticated adjacent-network attacker to access and take over live video and audio streams, compromising the confidentiality and integrity of camera media.

Metrics

CVSS Vector: CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.7

Product Status

Vendor TP-Link Systems Inc.
Product Tapo C325WB v2
Versions Default: unaffected
  • affected from 0 to V2_1.3.3 Build 260914 (excl.)

Credits

  • Andrey Charikov, Check Point Research finder

References

Problem Types

  • CWE-330 Use of Insufficiently Random Values CWE

Impacts

  • CAPEC-115 Authentication Bypass