Tenda

Cp3

11 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.4%
  • Veröffentlicht 13.08.2026 20:45:09
  • Zuletzt bearbeitet 18.08.2026 02:17:25

A vulnerability was detected in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C and TC3T15C up to 20260625. Affected by this vulnerability is an unknown functionality of the component RTSP/ONVIF. Performing a manipulation results ...

  • EPSS 0.31%
  • Veröffentlicht 13.08.2026 20:15:10
  • Zuletzt bearbeitet 14.08.2026 19:09:39

A security vulnerability has been detected in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C and TC3T15C up to 20260625. Affected is the function CWebSessionManager_ParseSession of the file /user/bin/Kylin of the component Kylin ...

  • EPSS 2.36%
  • Veröffentlicht 13.08.2026 19:45:09
  • Zuletzt bearbeitet 14.08.2026 19:09:39

A weakness has been identified in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C and TC3T15C up to 20260625. This impacts the function CAte::HandleCmd of the file Kylin of the component ATE Module. This manipulation causes comman...

  • EPSS 0.41%
  • Veröffentlicht 09.07.2026 17:17:00
  • Zuletzt bearbeitet 10.07.2026 17:41:47

A stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.91) allows an unauthenticated remote attacker to cause a denial of service via a crafted second SETUP request. After completing the OPTIONS, DESCRIBE,...

  • EPSS 0.4%
  • Veröffentlicht 09.07.2026 17:16:59
  • Zuletzt bearbeitet 10.07.2026 17:41:47

Tenda CP3 V3.0 firmware V31.1.9.91 does not validate the Content-Length header field in RTSP requests (including DESCRIBE, SETUP, and PLAY methods). When a request carrying a Content-Length header is received without a corresponding message body, the...

  • EPSS 0.41%
  • Veröffentlicht 09.07.2026 17:16:59
  • Zuletzt bearbeitet 10.07.2026 18:16:22

Tenda CP3 V3.0 firmware V31.1.9.91 contains a stack-based buffer overflow in the RTSP service. The device fails to validate the length of the clock= value in the Range header field when processing a PLAY request. An unauthenticated remote attacker wh...

  • EPSS 0.4%
  • Veröffentlicht 09.07.2026 17:16:59
  • Zuletzt bearbeitet 10.07.2026 17:41:47

A stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.91) allows an unauthenticated remote attacker to cause a denial of service via a crafted SETUP request. The RTSP service's second-stage URL routing pa...

  • EPSS 0.41%
  • Veröffentlicht 09.07.2026 00:00:00
  • Zuletzt bearbeitet 10.07.2026 17:41:47

A stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.91) allows an unauthenticated remote attacker to cause a denial of service via a crafted PLAY request.

  • EPSS 0.41%
  • Veröffentlicht 09.07.2026 00:00:00
  • Zuletzt bearbeitet 10.07.2026 17:41:47

A stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.991) allows an unauthenticated remote attacker to cause a denial of service via a crafted TEARDOWN request.

  • EPSS 0.32%
  • Veröffentlicht 09.07.2026 00:00:00
  • Zuletzt bearbeitet 10.07.2026 17:41:47

An improper input handling vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.91) causes the device to abruptly terminate the TCP connection with a RST packet when a request containing an oversized field value is received, without ...