CVE-2026-105673: Unauthenticated RTSP Tunnel Denial-of-Service Vulnerability in TP-Link Tapo C325WB
An unauthenticated denial-of-service vulnerability exists in Tapo C325WB v2 in the RTSP streaming service on TCP port 554 when the Camera Account feature is enabled. A crafted pair of RTSP-over-HTTP tunneling requests can cause memory corruption and crash the streaming daemon.
Successful exploitation may allow an unauthenticated adjacent-network attacker to disrupt live video and related streaming functions until the affected service recovers or restarts.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An unauthenticated attacker on an adjacent network can exploit it, provided the RTSP streaming service is reachable on TCP port 554 and the Camera Account feature is enabled.
Are devices using the default configuration affected?
The issue is specifically described as requiring the Camera Account feature to be enabled. The provided information does not state whether that feature is enabled by default.
What is the practical impact of a successful attack?
A crafted pair of RTSP-over-HTTP tunneling requests can corrupt memory and crash the streaming daemon. This can disrupt live video and related streaming functions until the service recovers or is restarted.
What can be done if a firmware update cannot be applied immediately?
Disable the Camera Account feature if it is not needed, and restrict adjacent-network access to the camera's RTSP service on TCP port 554.