Description
A stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.91) allows an unauthenticated remote attacker to cause a denial of service via a crafted SETUP request. The RTSP service's second-stage URL routing parser fails to validate the length of the URL field in the first SETUP request. By supplying a URL consisting of exactly four consecutive repetitions of a valid RTSP URL, an attacker can bypass first-stage format validation and trigger a stack buffer overflow, causing an immediate crash of the RTSP service process and rendering the device inaccessible to all clients on the local network.
Published: 2026-07-09
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A stack-based buffer overflow exists in the RTSP service of the Tenda CP3 V3.0 router (firmware V31.1.9.91). An unauthenticated attacker can send a specially crafted SETUP request containing a URL that repeats a valid RTSP URI four times, bypassing initial formatting checks and overflowing a stack buffer, which causes the RTSP process to crash and leaves the device inaccessible to all clients on the local network.

Affected Systems

The affected device is the Tenda CP3 V3.0 wireless router running firmware version V31.1.9.91. No other firmware versions or additional products are listed as affected.

Risk and Exploitability

The flaw has a CVSS base severity denial-of-service impact. The EPSS score is below 1%, indicating that widespread exploitation is not yet evident. The vulnerability can be exploited remotely without authentication by contacting the router’s RTSP service on port 554 and delivering the crafted SETUP request; only basic network connectivity is required, making the risk significant for local network availability.

Generated by OpenCVE AI on July 26, 2026 at 16:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the router to the latest Tenda CP3 firmware that incorporates the RTSP buffer overflow fix.
  • If an updated firmware is not available, block or disable the RTSP service by configuring the router’s firewall or NAT rules to drop traffic on port 554.
  • Monitor network traffic for anomalous RTSP requests and apply firmware updates as soon as they are released by Tenda.

Generated by OpenCVE AI on July 26, 2026 at 16:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 26 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Title Stack-based Buffer Overflow in Tenda CP3 RTSP Service Leads to Denial of Service

Wed, 22 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Title RTSP Buffer Overflow in Tenda CP3 V3.0 Causing Denial of Service

Thu, 16 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Title RTSP Buffer Overflow in Tenda CP3 V3.0 Causing Denial of Service

Wed, 15 Jul 2026 14:15:00 +0000

Type Values Removed Values Added
Title Tenda CP3 RTSP Buffer Overflow Leading to Denial of Service

Tue, 14 Jul 2026 04:45:00 +0000

Type Values Removed Values Added
Title Tenda CP3 RTSP Buffer Overflow Leading to Denial of Service

Sun, 12 Jul 2026 07:45:00 +0000

Type Values Removed Values Added
Title Stack of Tenda CP3 V3.0 Leading to Denial of Service

Fri, 10 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Title Stack of Tenda CP3 V3.0 Leading to Denial of Service

Thu, 09 Jul 2026 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Tenda
Tenda cp3
Vendors & Products Tenda
Tenda cp3

Thu, 09 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-121
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 09 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Description A stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.91) allows an unauthenticated remote attacker to cause a denial of service via a crafted SETUP request. The RTSP service's second-stage URL routing parser fails to validate the length of the URL field in the first SETUP request. By supplying a URL consisting of exactly four consecutive repetitions of a valid RTSP URL, an attacker can bypass first-stage format validation and trigger a stack buffer overflow, causing an immediate crash of the RTSP service process and rendering the device inaccessible to all clients on the local network.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-07-09T17:46:25.580Z

Reserved: 2026-06-08T00:00:00.000Z

Link: CVE-2026-51602

cve-icon Vulnrichment

Updated: 2026-07-09T17:46:06.551Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-26T16:15:17Z

Weaknesses
  • CWE-121

    Stack-based Buffer Overflow