{"id":"CVE-2026-105673","title":"An\nunauthenticated denial-of-service vulnerability exists in Tapo C325WB v2 in the\nRTSP streaming service on TCP port 554 when the Camera Account feature is\nenabled","summary":"An\nunauthenticated denial-of-service vulnerability exists in Tapo C325WB v2 in the\nRTSP streaming service on TCP port 554 when the Camera Account feature is\nenabled. A crafted pair of RTSP-over-HTTP tunneling requests can cause memory\nco…","severity":"none","cwe":["CWE-121"],"published":"2026-10-08","updated":"2026-10-08","sourceUpdated":"2026-10-08T23:16:57.520","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-105673","references":[{"url":"https://www.tp-link.com/en/support/download/tapo-c325wb/#Firmware-Release-Notes","label":"f23511db-6c3e-4e32-a477-6aa17d310630"},{"url":"https://www.tp-link.com/us/support/download/tapo-c325wb/#Firmware-Release-Notes","label":"f23511db-6c3e-4e32-a477-6aa17d310630"},{"url":"https://www.tp-link.com/us/support/faq/5333/","label":"f23511db-6c3e-4e32-a477-6aa17d310630"}],"tags":["nvd"],"ingestedAt":"2026-10-09T00:19:50.968Z","slug":"CVE-2026-105673","body":"## Overview\n\nAn\nunauthenticated denial-of-service vulnerability exists in Tapo C325WB v2 in the\nRTSP streaming service on TCP port 554 when the Camera Account feature is\nenabled. A crafted pair of RTSP-over-HTTP tunneling requests can cause memory\ncorruption and crash the streaming daemon. \n\n\n\n\n\n\n\n\n\nSuccessful\nexploitation may allow an unauthenticated adjacent-network attacker to disrupt\nlive video and related streaming functions until the affected service recovers\nor restarts.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}