Impact
A stack‑based buffer overflow exists in the RTSP service of the Tenda CP3 V3.0 firmware V31.1.9.91. The flaw is revealed after an unauthenticated attendee performs a normal OPTIONS, DESCRIBE, and first SETUP request to acquire a valid session ID, then sends a second SETUP request whose URL field contains four consecutive copies of a valid RTSP URL. Because the second‑stage URL parser does not validate the length of the URL field, the request overflows a stack buffer, causing the RTSP service process to crash. Splitting a single client’s request from other users, the process crash results in the router’s RTSP functionality becoming unavailable, effectively denying all local video‑streaming clients.
Affected Systems
Only the Tenda CP3 V3.0 router with firmware version V31.1.9.91 is affected. No other vendors or products are currently identified as impacted. The vulnerability is strictly limited to the RTSP component bundled in this firmware.
Risk and Exploitability
The CVSS score of 7.5 indicates a high impact, while the EPSS score of less than 1% demonstrates a very low probability of active exploitation. The vulnerability is not listed in CISA’s KEV catalog. The attack vector is remote and requires no authentication; any host that can reach the router’s RTSP interface can trigger the exploit by sending the malformed second SETUP request described above, causing the RTSP service to crash and denying service to all clients connected to the device’s RTSP interface.
OpenCVE Enrichment