CVE-2026-105673
Received Received - Intake

Denial-of-Service in Tapo C325WB v2 RTSP Service

Vulnerability report for CVE-2026-105673, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: TPLink

Description

An unauthenticated denial-of-service vulnerability exists in Tapo C325WB v2 in the RTSP streaming service on TCP port 554 when the Camera Account feature is enabled. A crafted pair of RTSP-over-HTTP tunneling requests can cause memory corruption and crash the streaming daemon.Β  Successful exploitation may allow an unauthenticated adjacent-network attacker to disrupt live video and related streaming functions until the affected service recovers or restarts.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
TP-Link Systems Inc. Tapo C325WB v2 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-121 A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an unauthenticated denial-of-service vulnerability in the Tapo C325WB v2 camera's RTSP streaming service on TCP port 554 when the Camera Account feature is enabled. It involves sending a crafted pair of RTSP-over-HTTP tunneling requests that cause memory corruption and crash the streaming daemon, disrupting live video and streaming functions until the service restarts.

Detection Guidance

To detect this vulnerability, check if the Tapo C325WB v2 device has TCP port 554 open and the Camera Account feature enabled. Use network scanning tools like nmap to verify port 554 status: nmap -p 554 <device_IP>. Monitor for crashes in the RTSP streaming service during RTSP-over-HTTP tunneling requests.

Impact Analysis

An unauthenticated attacker on the same network could exploit this to crash the camera's streaming service, causing live video feeds to stop working. The camera would need to be manually restarted or recover on its own, leading to temporary loss of monitoring or security footage.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR or HIPAA as it pertains to unauthenticated denial-of-service in a streaming service. However, disruption of video surveillance could impact data integrity or availability requirements under these regulations if the camera is used for monitoring regulated environments.

Mitigation Strategies

Disable the Camera Account feature on the Tapo C325WB v2 device if not required. Block external access to TCP port 554 using firewall rules. Update the device firmware to the latest version once a patch is released by TP-Link.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105673. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart