Executive brief
The Tenda CP3 security camera contains a flaw in its video streaming service. An attacker can send a specially crafted request to the camera to cause the streaming service to crash. This results in a loss of video monitoring capabilities, potentially allowing unauthorized physical activity to go unrecorded.
Technical details
A stack-based buffer overflow exists in the RTSP (Real Time Streaming Protocol) service of Tenda CP3 V3.0 firmware V31.1.9.91. The vulnerability is located in the processing of the 'Range' header field within a PLAY request, specifically due to a lack of length validation for the 'clock=' value. An unauthenticated remote attacker who has established a standard RTSP session handshake can trigger the overflow by providing an oversized string. This leads to a denial-of-service (DoS) condition by crashing the RTSP service. While the advisory focuses on the crash, stack overflows can sometimes lead to remote code execution depending on device protections.
Affected products
- Tenda CP3 V3.0 firmware V31.1.9.91
Timeline
- 2026-07-09: disclosed
- 2026-07-09: advisory