CVE-2026-105672EPSS p14.5%
CVE-2026-105672CVE-2026-105672
Description
TP-Link Tapo
C325WB V2 contains an unauthenticated authorization bypass vulnerability in the
HTTPS JSON API dispatcher on TCP port 443. An attacker on the adjacent network
can append an onboarding-scoped object to a JSON request to bypass session
verification and invoke privileged actions without authentication.
Successful
exploitation may allow an unauthenticated adjacent-network attacker to access
live video and audio, modify device settings, and obtain sensitive device
information or secrets.
Scoring
| EPSS | 0.24% probability of exploitation · percentile 14.5% · 2026-10-10T12:00:23Z |
| Last modified | 2026-10-09 |