Executive brief
A security vulnerability exists in the Tenda CP3 IP camera, a device used for home and office surveillance. An attacker on the same network can send a specially crafted series of video streaming requests to crash the camera's communication service. This results in a denial of service, making the camera inaccessible to the official mobile app and other monitoring software until the device is recovered.
Technical details
A stack-based buffer overflow exists in the RTSP service of Tenda CP3 V3.0 firmware V31.1.9.91. The vulnerability is located in the second-stage URL routing parser, which fails to validate the length of the URL field during a second SETUP request. To exploit this, an attacker must first complete the OPTIONS, DESCRIBE, and an initial legitimate SETUP handshake to obtain a valid session ID. By then sending a second SETUP request containing a URL composed of four consecutive repetitions of a valid RTSP URL, the attacker bypasses first-stage format validation and triggers the overflow. This results in an immediate crash of the RTSP process (typically on port 554), leading to a denial of service.
Affected products
- Tenda CP3 V3.0 V31.1.9.91
Timeline
- 2026-07-09: disclosed
- 2026-07-09: advisory