---
id: CVE-2026-105673
title: >-
  An

  unauthenticated denial-of-service vulnerability exists in Tapo C325WB v2 in
  the

  RTSP streaming service on TCP port 554 when the Camera Account feature is

  enabled
summary: >-
  An

  unauthenticated denial-of-service vulnerability exists in Tapo C325WB v2 in
  the

  RTSP streaming service on TCP port 554 when the Camera Account feature is

  enabled. A crafted pair of RTSP-over-HTTP tunneling requests can cause memory

  co…
severity: none
cwe:
  - CWE-121
published: '2026-10-08'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T23:16:57.520'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-105673'
references:
  - url: >-
      https://www.tp-link.com/en/support/download/tapo-c325wb/#Firmware-Release-Notes
    label: f23511db-6c3e-4e32-a477-6aa17d310630
  - url: >-
      https://www.tp-link.com/us/support/download/tapo-c325wb/#Firmware-Release-Notes
    label: f23511db-6c3e-4e32-a477-6aa17d310630
  - url: 'https://www.tp-link.com/us/support/faq/5333/'
    label: f23511db-6c3e-4e32-a477-6aa17d310630
tags:
  - nvd
ingestedAt: '2026-10-09T00:19:50.968Z'
---

## Overview

An
unauthenticated denial-of-service vulnerability exists in Tapo C325WB v2 in the
RTSP streaming service on TCP port 554 when the Camera Account feature is
enabled. A crafted pair of RTSP-over-HTTP tunneling requests can cause memory
corruption and crash the streaming daemon. 









Successful
exploitation may allow an unauthenticated adjacent-network attacker to disrupt
live video and related streaming functions until the affected service recovers
or restarts.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
