Denial-of-Service Vulnerability in Tapo C325WB by TP-Link
CVE-2026-105673

7.1HIGH

Key Information:

Vendor
CVE Published:
8 October 2026

What is CVE-2026-105673?

An unauthenticated denial-of-service vulnerability has been identified in the Tapo C325WB camera that can be exploited when the Camera Account feature is enabled. By sending carefully crafted RTSP-over-HTTP tunneling requests to the device's RTSP streaming service on TCP port 554, an attacker could cause memory corruption, leading to a crash of the streaming daemon. This disruption impacts live video functions, rendering the streaming services inoperable until the device is restarted or the affected service recovers. Organizations using this camera model should apply necessary patches to mitigate this risk.

Affected Version(s)

Tapo C325WB v2 0

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Andrey Charikov, Check Point Research
.