Executive brief
A security vulnerability has been identified in the Tenda CP3 security camera. This flaw affects the Real Time Streaming Protocol (RTSP) service, which is responsible for handling video streams. An unauthorized person could remotely crash the camera, causing it to stop recording or providing a live feed, which could disrupt security monitoring operations.
Technical details
A stack-based buffer overflow exists within the RTSP service of the Tenda CP3 V3.0 security camera running firmware version V31.1.9.91. The vulnerability is triggered when the service processes a specially crafted RTSP 'PLAY' request. An unauthenticated remote attacker can exploit this by sending a malicious packet over the network to the device. Successful exploitation results in a crash of the RTSP service or the entire device, leading to a denial-of-service (DoS) condition. While the primary impact is availability, stack overflows can sometimes lead to remote code execution depending on the presence of modern exploit mitigations.
Affected products
- Tenda CP3 V3.0 V31.1.9.91
Timeline
- 2026-07-09: disclosed
- 2026-07-09: advisory