Impact
An improper handling of RTSP request fields in Tenda CP3 routers built on firmware V31.1.9.91 (V3.0) causes the device to abruptly terminate the TCP connection with a reset packet when a request contains an oversized field value in either the URL or header fields. Because the server issues no RFC 2326‑compliant error response, legitimate clients are forced to disconnect immediately, resulting in a denial of service to any client attempting to use RTSP. The flaw is classified as CWE‑20 and does not need authentication or privilege escalation to be exercised.
Affected Systems
Only the Tenda CP3 router model running firmware V31.1.9.91 is affected, and the vulnerability is limited to the RTSP service listening on TCP 554. Core routing, Wi‑Fi management, and other services are not impacted by this input‑validation bug.
Risk and Exploitability
With a CVSS score of 7.5 the severity is high, and the EPSS score of < 1% suggests that exploitation is unlikely in the wild. The attack can be carried out remotely from any host with network reach to the router’s RTSP interface; the only requirement is to send an RTSP request with an oversized field value, which the device accepts and then resets the connection. Since the flaw is not listed in the CISA KEV catalog, no formal advisories are currently in place. The likely attack vector is remote, unauthenticated traffic directed to port 554, inferred from the description of the RTSP service being publicly exposed.
OpenCVE Enrichment