Vulnerability intelligence
CVE-2026-105673
An unauthenticated denial-of-service vulnerability exists in Tapo C325WB v2 in the RTSP streaming service on TCP port 554 when the Camera Account feature is enabled. A crafted pair of RTSP-over-HTTP tunneling requests can cause memory corruption and crash the streaming daemon. Successful exploitation may allow an unauthenticated adjacent-network attacker to disrupt live video and related streaming functions until the affected service recovers or restarts.
CVSS Score
7.1
High
EPSS — Exploit Probability
—
Awaiting FIRST.org data · checked 2026-10-09
Exploitation
Not in CISA KEV
KEV does not include every exploited vulnerability
Remediation
Patch available
Vendor fix published
1 article across 1 outlet · first covered Oct 9, 2026 · latest Oct 9, 2026
Coverage timeline
-
TP-Link Patches Tapo Cameras Flaws That Could Let Attackers Hijack Video Streamssecurityonline.info · Oct 9, 2026