Denial-of-Service Vulnerability in Tapo C325WB by TP-Link
CVE-2026-105673
7.1HIGH
What is CVE-2026-105673?
An unauthenticated denial-of-service vulnerability has been identified in the Tapo C325WB camera that can be exploited when the Camera Account feature is enabled. By sending carefully crafted RTSP-over-HTTP tunneling requests to the device's RTSP streaming service on TCP port 554, an attacker could cause memory corruption, leading to a crash of the streaming daemon. This disruption impacts live video functions, rendering the streaming services inoperable until the device is restarted or the affected service recovers. Organizations using this camera model should apply necessary patches to mitigate this risk.
Affected Version(s)
Tapo C325WB v2 0
References
CVSS V4
Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Andrey Charikov, Check Point Research
