Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-105673— Unauthenticated RTSP Tunnel Denial-of-Service Vulnerability in TP-Link Tapo C325WB

Quick assessment

Affected
TP-Link Systems Inc. Tapo C325WB v2
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Tapo C325WB v2 中,当启用“摄像头账户”(Camera Account)功能时,基于 TCP 端口 554 的 RTSP 流媒体服务存在一个未经身份验证的拒绝服务(DoS)漏洞。攻击者通过构造特定的 RTSP-over-HTTP 隧道请求,可导致内存损坏并致使流媒体守护进程崩溃。 成功利用该漏洞可使未经身份验证的相邻网络攻击者中断实时视频流及相关流媒体功能,直到受影响的服务恢复或重新启动。

CVSS 7.1 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-105673

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Unauthenticated RTSP Tunnel Denial-of-Service Vulnerability in TP-Link Tapo C325WB
Source: CVE Program / CVE List V5
Vulnerability Description
An unauthenticated denial-of-service vulnerability exists in Tapo C325WB v2 in the RTSP streaming service on TCP port 554 when the Camera Account feature is enabled. A crafted pair of RTSP-over-HTTP tunneling requests can cause memory corruption and crash the streaming daemon.  Successful exploitation may allow an unauthenticated adjacent-network attacker to disrupt live video and related streaming functions until the affected service recovers or restarts.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
栈缓冲区溢出
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
TP-Link Systems Inc. Tapo C325WB v2 0 ~ V2_1.3.3 Build 260914 -

II. Public POCs for CVE-2026-105673

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-105673

请登录查看更多情报信息。

Other References for CVE-2026-105673 (3)

Same Patch Batch · TP-Link Systems Inc. · 2026-10-08 · 3 CVEs total

CVE-2026-105674 8.7 HIGH Predictable Media Stream Pre-Shared Key Vulnerability in TP-Link Tapo C325WB
CVE-2026-105672 8.7 HIGH Unauthenticated JSON API Authorization Bypass Vulnerability in TP-Link Tapo C325WB

IV. Related Vulnerabilities

V. Comments for CVE-2026-105673

No comments yet


Leave a comment