Description
A stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.991) allows an unauthenticated remote attacker to cause a denial of service via a crafted TEARDOWN request.
Published: 2026-07-09
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A stack-based buffer overflow (CWE-121) exists in the RTSP service of the Tenda CP3 V3.0 router. The flaw is triggered by a specially crafted TEARDOWN request, which causes the service to crash. Because the attack does not require authentication and only requires an open RTSP port, any host that can reach the device over the network can exploit it. The result is a loss of availability for the RTSP service without compromising confidentiality or integrity.

Affected Systems

The vulnerability affects the Tenda CP3 V3.0 router running firmware version V31.1.9.991. No other models or firmware revisions have been reported as affected in the current advisory.

Risk and Exploitability

The CVSS score of 7.5 classifies the issue as high severity, while the EPSS score of <1% indicates a very low probability of exploitation at present. The vulnerability is not listed in CISA’s KEV catalog. The exploit path is remote network; an attacker can send the TEARDOWN packet without authentication to induce a service crash. Because it only causes a denial of service, the impact is limited to availability loss of the RTSP service.

Generated by OpenCVE AI on July 28, 2026 at 08:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Block or disable the RTSP service on the device or at the network perimeter to prevent remote access.
  • If a firmware update that resolves the issue is released by the vendor, apply the update to all affected devices.
  • Monitor network traffic for unexpected TEARDOWN requests and investigate any incidents promptly.

Generated by OpenCVE AI on July 28, 2026 at 08:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title Stack-based Buffer Overflow in Tenda CP3 RTSP Service Leading to Denial of Service

Fri, 24 Jul 2026 09:00:00 +0000

Type Values Removed Values Added
Title RTSP Stack-Based Buffer Overflow Exposes Tenda CP3 to Remote Denial of Service

Thu, 16 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Title RTSP Stack-Based Buffer Overflow Exposes Tenda CP3 to Remote Denial of Service

Mon, 13 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Title Stack-based Buffer Overflow in RTSP Service Enables Remote Denial of Service

Sun, 12 Jul 2026 07:45:00 +0000

Type Values Removed Values Added
Title Stack-based Buffer Overflow in RTSP Service Enables Remote Denial of Service

Sat, 11 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Title Stack-based Buffer Overflow in RTSP Service Enables Remote Denial of Service on Tenda CP3

Fri, 10 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Title Stack-based Buffer Overflow in RTSP Service Enables Remote Denial of Service on Tenda CP3

Fri, 10 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Tenda
Tenda cp3 V3
Vendors & Products Tenda
Tenda cp3 V3

Thu, 09 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-121
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 09 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Description A stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.991) allows an unauthenticated remote attacker to cause a denial of service via a crafted TEARDOWN request.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-07-09T17:39:01.874Z

Reserved: 2026-06-08T00:00:00.000Z

Link: CVE-2026-51605

cve-icon Vulnrichment

Updated: 2026-07-09T17:38:46.899Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-28T09:00:06Z

Weaknesses
  • CWE-121

    Stack-based Buffer Overflow