PatchSiren cyber security CVE debrief
CVE-2026-105673 TP-Link Systems Inc. CVE debrief
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-10-08T22:21:28.785Z and has not been modified since then. An unauthenticated denial-of-service vulnerability exists in Tapo C325WB v2 in the RTSP streaming service on TCP port 554 when the Camera Account feature is enabled. A crafted pair of RTSP-over-HTTP tunneling requests can cause memory corruption and crash the streaming daemon. Successful exploitation may allow an unauthenticated adjacent-network attacker to disrupt live video and related streaming functions until the affected service recovers or restarts. Defenders responsible for TP-Link Tapo C325WB v2 devices, verify 3
- Vendor
- TP-Link Systems Inc.
- Product
- Tapo C325WB v2
- CVSS
- HIGH 7.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-08
- Original CVE updated
- 2026-10-09
- Advisory published
- 2026-10-08
- Advisory updated
- 2026-10-09
Who should care
Defenders responsible for TP-Link Tapo C325WB v2 devices, particularly those with the Camera Account feature enabled, should assess exposure and potential disruptions to live video and streaming functions.
Why it matters
Defenders should prioritize verifying exposure of Tapo C325WB v2 devices with the Camera Account feature enabled and assessing the impact of potential disruptions to live video and streaming functions. The CVE record and source item provide details on the unauthenticated denial-of-service vulnerability, but the corpus does not establish versions beyond V2_1.3.3 Build 260914 or provide specific details on exploitation, impact, or remediation beyond disrupting live video and streaming functions.
- Potential disruption to live video and streaming functions
- Possible adjacent-network attacks
- Verification of exposure and impact required
- Remediation priority for affected versions
Technical summary
An unauthenticated denial-of-service vulnerability exists in Tapo C325WB v2 in the RTSP streaming service on TCP port 554 when the Camera Account feature is enabled. A crafted pair of RTSP-over-HTTP tunneling requests can cause memory corruption and crash the streaming daemon. Successful exploitation may allow an unauthenticated adjacent-network attacker to disrupt live video and related streaming functions until the affected service recovers or restarts. The vulnerability affects Tapo C325WB v2 devices with the Camera Account feature enabled, and defenders should prioritize verifying exposure and assessing potential disruptions.
Defensive priority
Defenders should prioritize verifying exposure of Tapo C325WB v2 devices with the Camera Account feature enabled and assessing the impact of potential disruptions to live video and streaming functions.
Recommended defensive actions
- Verify exposure of Tapo C325WB v2 devices with the Camera Account feature enabled
- Assess the impact of potential disruptions to live video and streaming functions
- Apply firmware updates to affected versions (V2_1.3.3 Build 260914 or earlier)
- Monitor for potential adjacent-network attacks
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
The CVE record and source item provide details on the unauthenticated denial-of-service vulnerability in Tapo C325WB v2. However, the corpus does not establish versions beyond V2_1.3.3 Build 260914 or provide specific details on exploitation, impact, or remediation beyond disrupting live video and streaming functions.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-105673 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-105673
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-105673 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-105673
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Unauthenticated RTSP Tunnel Denial-of-Service Vulnerability in TP-Link Tapo C325WB
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/105xxx/CVE-2026-105673.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://www.tp-link.com/us/support/download/tapo-c325wb/
Supplemental source - patch
-
Source reference
Unverified legacy reference
URL: https://www.tp-link.com/en/support/download/tapo-c325wb/
Supplemental source - patch
-
Source reference
Unverified legacy reference
URL: https://www.tp-link.com/us/support/faq/5333/
Supplemental source - vendor-advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.