Description
TP-Link Tapo
C325WB V2 generates the pre-shared key used by its local media streaming
service with a time-seeded pseudo-random number generator, making the key
predictable and recoverable. An unauthenticated attacker on the adjacent
network can recover the key and authenticate to the media streaming service
without valid user credentials.
Successful
exploitation may allow an unauthenticated adjacent-network attacker to access
and take over live video and audio streams, compromising the confidentiality
and integrity of camera media.
C325WB V2 generates the pre-shared key used by its local media streaming
service with a time-seeded pseudo-random number generator, making the key
predictable and recoverable. An unauthenticated attacker on the adjacent
network can recover the key and authenticate to the media streaming service
without valid user credentials.
Successful
exploitation may allow an unauthenticated adjacent-network attacker to access
and take over live video and audio streams, compromising the confidentiality
and integrity of camera media.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Thu, 08 Oct 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | TP-Link Tapo C325WB V2 generates the pre-shared key used by its local media streaming service with a time-seeded pseudo-random number generator, making the key predictable and recoverable. An unauthenticated attacker on the adjacent network can recover the key and authenticate to the media streaming service without valid user credentials. Successful exploitation may allow an unauthenticated adjacent-network attacker to access and take over live video and audio streams, compromising the confidentiality and integrity of camera media. | |
| Title | Predictable Media Stream Pre-Shared Key Vulnerability in TP-Link Tapo C325WB | |
| Weaknesses | CWE-330 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: TPLink
Published:
Updated: 2026-10-08T22:21:45.875Z
Reserved: 2026-10-05T17:48:07.907Z
Link: CVE-2026-105674
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-330
Use of Insufficiently Random Values