{"id":"CVE-2026-105672","title":"TP-Link Tapo\nC325WB V2 contains an unauthenticated authorization bypass vulnerability in the\nHTTPS JSON API dispatcher on TCP port 443","summary":"TP-Link Tapo\nC325WB V2 contains an unauthenticated authorization bypass vulnerability in the\nHTTPS JSON API dispatcher on TCP port 443. An attacker on the adjacent network\ncan append an onboarding-scoped object to a JSON request to bypas…","severity":"none","cwe":["CWE-287"],"published":"2026-10-08","updated":"2026-10-08","sourceUpdated":"2026-10-08T23:16:57.333","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-105672","references":[{"url":"https://www.tp-link.com/en/support/download/tapo-c325wb/#Firmware-Release-Notes","label":"f23511db-6c3e-4e32-a477-6aa17d310630"},{"url":"https://www.tp-link.com/us/support/download/tapo-c325wb/#Firmware-Release-Notes","label":"f23511db-6c3e-4e32-a477-6aa17d310630"},{"url":"https://www.tp-link.com/us/support/faq/5333/","label":"f23511db-6c3e-4e32-a477-6aa17d310630"}],"tags":["nvd"],"ingestedAt":"2026-10-09T00:19:50.967Z","slug":"CVE-2026-105672","body":"## Overview\n\nTP-Link Tapo\nC325WB V2 contains an unauthenticated authorization bypass vulnerability in the\nHTTPS JSON API dispatcher on TCP port 443. An attacker on the adjacent network\ncan append an onboarding-scoped object to a JSON request to bypass session\nverification and invoke privileged actions without authentication. \n\n\n\n\n\nSuccessful\nexploitation may allow an unauthenticated adjacent-network attacker to access\nlive video and audio, modify device settings, and obtain sensitive device\ninformation or secrets.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}