An
unauthenticated denial-of-service vulnerability exists in Tapo C325WB v2 in the
RTSP streaming service on TCP port 554 when the Camera Account feature is
enabled. A crafted pair of RTSP-over-HTTP tunneling requests can cause memory
corruption and crash the streaming daemon.
Successful
exploitation may allow an unauthenticated adjacent-network attacker to disrupt
live video and related streaming functions until the affected service recovers
or restarts.