---
id: CVE-2026-105672
title: >-
  TP-Link Tapo

  C325WB V2 contains an unauthenticated authorization bypass vulnerability in
  the

  HTTPS JSON API dispatcher on TCP port 443
summary: >-
  TP-Link Tapo

  C325WB V2 contains an unauthenticated authorization bypass vulnerability in
  the

  HTTPS JSON API dispatcher on TCP port 443. An attacker on the adjacent network

  can append an onboarding-scoped object to a JSON request to bypas…
severity: none
cwe:
  - CWE-287
published: '2026-10-08'
updated: '2026-10-09'
sourceUpdated: '2026-10-09T16:45:01.980'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-105672'
references:
  - url: >-
      https://www.tp-link.com/en/support/download/tapo-c325wb/#Firmware-Release-Notes
    label: f23511db-6c3e-4e32-a477-6aa17d310630
  - url: >-
      https://www.tp-link.com/us/support/download/tapo-c325wb/#Firmware-Release-Notes
    label: f23511db-6c3e-4e32-a477-6aa17d310630
  - url: 'https://www.tp-link.com/us/support/faq/5333/'
    label: f23511db-6c3e-4e32-a477-6aa17d310630
tags:
  - nvd
ingestedAt: '2026-10-09T00:19:50.967Z'
---

## Overview

TP-Link Tapo
C325WB V2 contains an unauthenticated authorization bypass vulnerability in the
HTTPS JSON API dispatcher on TCP port 443. An attacker on the adjacent network
can append an onboarding-scoped object to a JSON request to bypass session
verification and invoke privileged actions without authentication. 





Successful
exploitation may allow an unauthenticated adjacent-network attacker to access
live video and audio, modify device settings, and obtain sensitive device
information or secrets.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
