CVE-2026-105672: Unauthenticated JSON API Authorization Bypass Vulnerability in TP-Link Tapo C325WB
TP-Link Tapo C325WB V2 contains an unauthenticated authorization bypass vulnerability in the HTTPS JSON API dispatcher on TCP port 443. An attacker on the adjacent network can append an onboarding-scoped object to a JSON request to bypass session verification and invoke privileged actions without authentication.
Successful exploitation may allow an unauthenticated adjacent-network attacker to access live video and audio, modify device settings, and obtain sensitive device information or secrets.
Affected Software
Event History
Frequently Asked Questions
Who can realistically exploit this issue?
An attacker must be on the adjacent network and able to reach the camera's HTTPS JSON API on TCP port 443. No authentication is required once they can send the crafted JSON request.
What access could an attacker gain?
Successful exploitation may allow access to live video and audio, modification of device settings, and retrieval of sensitive device information or secrets.
What should be prioritized for mitigation?
Restrict access to the camera's TCP port 443 interface from untrusted adjacent-network devices and apply any relevant firmware updates referenced in TP-Link's firmware release notes.