Junglewise Threat Intelligence

CVE-2026-51606: Tenda CP3 improper input handling in RTSP service

CVE-2026-51606 · Severity: info · CVSS 3.7 · Published 2026-07-09

Vendors: Tenda.

Executive brief

The Tenda CP3 security camera contains a flaw in how it handles video streaming requests. An attacker can send a specially crafted request that causes the camera to abruptly drop the connection. This can lead to minor service disruptions or difficulties in maintaining a stable video stream.

Technical details

An improper input handling vulnerability exists in the RTSP (Real Time Streaming Protocol) service of Tenda CP3 V3.0 devices running firmware V31.1.9.91. The device fails to properly process oversized field values in the request-line URL or header fields. Instead of returning a standard RFC 2326-compliant error response, the service abruptly terminates the TCP connection with a RST packet. This behavior can be triggered by a remote attacker over the network without authentication, leading to a localized denial-of-service for the RTSP session.

Affected products

  • Tenda CP3 V3.0 firmware V31.1.9.91

Timeline

  • 2026-07-09: disclosed
  • 2026-07-09: advisory

References