Impact
The vulnerability is a stack-based buffer overflow in Tenda CP3's RTSP service. When a PLAY request contains a Range header with a clock= value longer than expected, the service fails to validate the length, leading to a crash. Attackers can trigger this by establishing a standard RTSP session without authentication and sending a crafted request. The crash results in denial of service, interrupting the device’s ability to stream video.
Affected Systems
Affected is the Tenda CP3 V3.0 firmware V31.1.9.91. No other versions explicitly listed. The flaw exists on that specific firmware build.
Risk and Exploitability
The CVSS score is 7.5, but the lack of authentication requirement and the straightforward exploit craftability suggest a high risk of exploitation. The EPSS score is < 1%, and the vulnerability is not present in the CISA KEV catalog, indicating no known active exploits yet. However, because the flaw causes a service crash, an attacker could repeatedly trigger the vulnerability to achieve consistent denial of service. The attack requires only standard RTSP communication, making it feasible over the network.
OpenCVE Enrichment