Executive brief
A security vulnerability exists in the Tenda CP3 security camera that allows an unauthorized person to crash the device remotely. By sending a specifically formatted network request to the camera's video streaming service, an attacker can cause the device to stop responding and become inaccessible to all users on the local network. This results in a complete loss of video monitoring capabilities until the device is recovered.
Technical details
A stack-based buffer overflow exists in the RTSP service of Tenda CP3 V3.0 firmware V31.1.9.91. The vulnerability is located in the second-stage URL routing parser, which fails to validate the length of the URL field during the initial SETUP request. An unauthenticated remote attacker can bypass first-stage format validation by supplying a URL containing four consecutive repetitions of a valid RTSP URL. This triggers the overflow, leading to a process crash and a denial-of-service (DoS) condition for the device's RTSP functionality.
Affected products
- Tenda CP3 V3.0 V31.1.9.91
Timeline
- 2026-07-09: disclosed
- 2026-07-09: advisory