{"id":"CVE-2026-105674","title":"TP-Link Tapo\nC325WB V2 generates the pre-shared key used by its local media streaming\nservice with a time-seeded pseudo-random number generator, making the key\npredictable and recoverable","summary":"TP-Link Tapo\nC325WB V2 generates the pre-shared key used by its local media streaming\nservice with a time-seeded pseudo-random number generator, making the key\npredictable and recoverable. An unauthenticated attacker on the adjacent\nnetw…","severity":"none","cwe":["CWE-330"],"published":"2026-10-08","updated":"2026-10-08","sourceUpdated":"2026-10-08T23:16:57.663","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-105674","references":[{"url":"https://www.tp-link.com/en/support/download/tapo-c325wb/#Firmware-Release-Notes","label":"f23511db-6c3e-4e32-a477-6aa17d310630"},{"url":"https://www.tp-link.com/us/support/download/tapo-c325wb/#Firmware-Release-Notes","label":"f23511db-6c3e-4e32-a477-6aa17d310630"},{"url":"https://www.tp-link.com/us/support/faq/5333/","label":"f23511db-6c3e-4e32-a477-6aa17d310630"}],"tags":["nvd"],"ingestedAt":"2026-10-09T00:19:50.968Z","slug":"CVE-2026-105674","body":"## Overview\n\nTP-Link Tapo\nC325WB V2 generates the pre-shared key used by its local media streaming\nservice with a time-seeded pseudo-random number generator, making the key\npredictable and recoverable. An unauthenticated attacker on the adjacent\nnetwork can recover the key and authenticate to the media streaming service\nwithout valid user credentials. \n\n\n\n\n\n\n\n\n\nSuccessful\nexploitation may allow an unauthenticated adjacent-network attacker to access\nand take over live video and audio streams, compromising the confidentiality\nand integrity of camera media.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}