Impact
The vulnerability is a stack-based buffer overflow (CWE-121) in the RTSP service's handling of PLAY commands on the Tenda CP3 V31.1.9.91. An unauthenticated remote attacker can craft a PLAY request that overflows an internal buffer, crashing the RTSP daemon and stopping all RTSP connections. The result is a denial of service for any client using the RTSP service, while confidentiality and integrity are not affected.
Affected Systems
The Tenda CP3 V3.0 router with firmware version V31.1.9.91 is affected. No other vendors or products are listed as impacted.
Risk and Exploitability
The CVSS score of 7.5 reflects high severity for availability, and the EPSS score of less than 1% indicates a very low probability of exploitation. Because authentication is not required, any host that can reach the RTSP port (typically 554) can potentially exploit the flaw. The vulnerability is not listed in CISA’s KEV catalog, suggesting no known active exploitation campaigns. Overall, the risk is moderate, driven primarily by the availability impact and the fact that the flaw is remotely exploitable without credentials.
OpenCVE Enrichment