Description
Tenda CP3 V3.0 firmware V31.1.9.91 contains a stack-based buffer overflow in the RTSP service. The device fails to validate the length of the clock= value in the Range header field when processing a PLAY request. An unauthenticated remote attacker who has completed a standard RTSP session handshake can send a PLAY request with an excessively long clock= value to cause the RTSP service to crash.
Published: 2026-07-09
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a stack-based buffer overflow in Tenda CP3's RTSP service. When a PLAY request contains a Range header with a clock= value longer than expected, the service fails to validate the length, leading to a crash. Attackers can trigger this by establishing a standard RTSP session without authentication and sending a crafted request. The crash results in denial of service, interrupting the device’s ability to stream video.

Affected Systems

Affected is the Tenda CP3 V3.0 firmware V31.1.9.91. No other versions explicitly listed. The flaw exists on that specific firmware build.

Risk and Exploitability

The CVSS score is 7.5, but the lack of authentication requirement and the straightforward exploit craftability suggest a high risk of exploitation. The EPSS score is < 1%, and the vulnerability is not present in the CISA KEV catalog, indicating no known active exploits yet. However, because the flaw causes a service crash, an attacker could repeatedly trigger the vulnerability to achieve consistent denial of service. The attack requires only standard RTSP communication, making it feasible over the network.

Generated by OpenCVE AI on July 25, 2026 at 20:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the device to a firmware version that fixes the buffer overflow.
  • If an update is not available, disable or block the RTSP service on the network to prevent unauthenticated access.
  • Monitor device logs and network traffic for anomalous RTSP activity indicative of exploitation attempts.

Generated by OpenCVE AI on July 25, 2026 at 20:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 25 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title Stack-based Buffer Overflow in Tenda CP3 RTSP Service

Wed, 22 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Title Stack-based Buffer Overflow in Tenda CP3 RTSP Service Leading to Denial of Service

Wed, 15 Jul 2026 05:30:00 +0000

Type Values Removed Values Added
Title Stack-based Buffer Overflow in Tenda CP3 RTSP Service Leading to Denial of Service

Mon, 13 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Title Tenda CP3 RTSP Buffer Overflow Enables Remote Denial of Service

Mon, 13 Jul 2026 01:45:00 +0000

Type Values Removed Values Added
Title Tenda CP3 RTSP Buffer Overflow Enables Remote Denial of Service

Sun, 12 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Title Tenda CP3 RTSP Buffer Overflow Allowing Remote Denial of Service
Weaknesses CWE-120

Fri, 10 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-121
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 10 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Title Tenda CP3 RTSP Buffer Overflow Allowing Remote Denial of Service
Weaknesses CWE-120

Thu, 09 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Tenda
Tenda cp3
Vendors & Products Tenda
Tenda cp3

Thu, 09 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Description Tenda CP3 V3.0 firmware V31.1.9.91 contains a stack-based buffer overflow in the RTSP service. The device fails to validate the length of the clock= value in the Range header field when processing a PLAY request. An unauthenticated remote attacker who has completed a standard RTSP session handshake can send a PLAY request with an excessively long clock= value to cause the RTSP service to crash.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-07-10T17:28:02.194Z

Reserved: 2026-06-08T00:00:00.000Z

Link: CVE-2026-51601

cve-icon Vulnrichment

Updated: 2026-07-10T17:24:50.920Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-25T20:45:02Z

Weaknesses
  • CWE-121

    Stack-based Buffer Overflow