Description
A stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.91) allows an unauthenticated remote attacker to cause a denial of service via a crafted PLAY request.
Published: 2026-07-09
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a stack-based buffer overflow (CWE-121) in the RTSP service's handling of PLAY commands on the Tenda CP3 V31.1.9.91. An unauthenticated remote attacker can craft a PLAY request that overflows an internal buffer, crashing the RTSP daemon and stopping all RTSP connections. The result is a denial of service for any client using the RTSP service, while confidentiality and integrity are not affected.

Affected Systems

The Tenda CP3 V3.0 router with firmware version V31.1.9.91 is affected. No other vendors or products are listed as impacted.

Risk and Exploitability

The CVSS score of 7.5 reflects high severity for availability, and the EPSS score of less than 1% indicates a very low probability of exploitation. Because authentication is not required, any host that can reach the RTSP port (typically 554) can potentially exploit the flaw. The vulnerability is not listed in CISA’s KEV catalog, suggesting no known active exploitation campaigns. Overall, the risk is moderate, driven primarily by the availability impact and the fact that the flaw is remotely exploitable without credentials.

Generated by OpenCVE AI on July 28, 2026 at 08:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware update for the Tenda CP3 V3.0 that addresses the RTSP buffer overflow.
  • If a patch is not available, use firewall rules or access‑control traffic to the RTSP service (port 554).
  • If the RTSP service is not required for operation, disable it entirely until a confirmed fix is deployed.

Generated by OpenCVE AI on July 28, 2026 at 08:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title Buffer Overflow in Tenda CP3 RTSP Service Causing Remote Denial of Service

Thu, 23 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
Title Buffer Overflow in Tenda CP3 RTSP Service Causing Remote Denial of Service

Tue, 21 Jul 2026 01:45:00 +0000

Type Values Removed Values Added
Title Stack-Based Buffer Overflow in Tenda CP3 RTSP Service Causes Remote Denial of Service

Wed, 15 Jul 2026 05:15:00 +0000

Type Values Removed Values Added
Title Stack-Based Buffer Overflow in Tenda CP3 RTSP Service Causes Remote Denial of Service

Tue, 14 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Title Stack-Based Buffer Overflow in Tenda CP3 RTSP Service Enables Unauthenticated DoS

Mon, 13 Jul 2026 01:45:00 +0000

Type Values Removed Values Added
Title Stack-Based Buffer Overflow in Tenda CP3 RTSP Service Enables Unauthenticated DoS

Sat, 11 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
Title Remote Denial of Service via Unauthenticated RTSP Buffer Overflow on Tenda CP3 V3.0

Fri, 10 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title Remote Denial of Service via Unauthenticated RTSP Buffer Overflow on Tenda CP3 V3.0

Thu, 09 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-121
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 09 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Tenda
Tenda cp3
Vendors & Products Tenda
Tenda cp3

Thu, 09 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Description A stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.91) allows an unauthenticated remote attacker to cause a denial of service via a crafted PLAY request.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-07-09T17:36:57.086Z

Reserved: 2026-06-08T00:00:00.000Z

Link: CVE-2026-51604

cve-icon Vulnrichment

Updated: 2026-07-09T17:36:12.936Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-28T09:00:06Z

Weaknesses
  • CWE-121

    Stack-based Buffer Overflow