Impact
A stack-based buffer overflow (CWE-121) exists in the RTSP service of the Tenda CP3 V3.0 router. The flaw is triggered by a specially crafted TEARDOWN request, which causes the service to crash. Because the attack does not require authentication and only requires an open RTSP port, any host that can reach the device over the network can exploit it. The result is a loss of availability for the RTSP service without compromising confidentiality or integrity.
Affected Systems
The vulnerability affects the Tenda CP3 V3.0 router running firmware version V31.1.9.991. No other models or firmware revisions have been reported as affected in the current advisory.
Risk and Exploitability
The CVSS score of 7.5 classifies the issue as high severity, while the EPSS score of <1% indicates a very low probability of exploitation at present. The vulnerability is not listed in CISA’s KEV catalog. The exploit path is remote network; an attacker can send the TEARDOWN packet without authentication to induce a service crash. Because it only causes a denial of service, the impact is limited to availability loss of the RTSP service.
OpenCVE Enrichment