Description


TP-Link Tapo C325WB V2 generates the pre-shared key used by its local media streaming service with a time-seeded pseudo-random number generator, making the key predictable and recoverable. An unauthenticated attacker on the adjacent network can recover the key and authenticate to the media streaming service without valid user credentials.  Successful exploitation may allow an unauthenticated adjacent-network attacker to access and take over live video and audio streams, compromising the confidentiality and integrity of camera media.

Related CPE's


Could not find any relations

Weaknesses


f23511db-6c3e-4e32-a477-6aa17d310630

Secondary

CWE-330

CVSS impact metrics


CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

8.7 · High

Information


Source identifier

f23511db-6c3e-4e32-a477-6aa17d310630

Vulnerability status

Deferred

Published

2026-10-08T23:16:57.663Z

19 hours ago

Last modified

2026-10-09T16:45:01.980Z

1 hour ago