CVE-2026-105673EPSS p9.3%
CVE-2026-105673CVE-2026-105673
Description
An
unauthenticated denial-of-service vulnerability exists in Tapo C325WB v2 in the
RTSP streaming service on TCP port 554 when the Camera Account feature is
enabled. A crafted pair of RTSP-over-HTTP tunneling requests can cause memory
corruption and crash the streaming daemon.
Successful
exploitation may allow an unauthenticated adjacent-network attacker to disrupt
live video and related streaming functions until the affected service recovers
or restarts.
Scoring
| EPSS | 0.20% probability of exploitation · percentile 9.3% · 2026-10-10T12:00:23Z |
| Last modified | 2026-10-09 |