Tenda

Cp3

17 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.4%
  • Veröffentlicht 09.07.2026 17:16:59
  • Zuletzt bearbeitet 10.07.2026 17:41:47

A stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.91) allows an unauthenticated remote attacker to cause a denial of service via a crafted SETUP request. The RTSP service's second-stage URL routing pa...

  • EPSS 0.41%
  • Veröffentlicht 09.07.2026 17:16:59
  • Zuletzt bearbeitet 10.07.2026 18:16:22

Tenda CP3 V3.0 firmware V31.1.9.91 contains a stack-based buffer overflow in the RTSP service. The device fails to validate the length of the clock= value in the Range header field when processing a PLAY request. An unauthenticated remote attacker wh...

  • EPSS 0.4%
  • Veröffentlicht 09.07.2026 17:16:59
  • Zuletzt bearbeitet 10.07.2026 17:41:47

Tenda CP3 V3.0 firmware V31.1.9.91 does not validate the Content-Length header field in RTSP requests (including DESCRIBE, SETUP, and PLAY methods). When a request carrying a Content-Length header is received without a corresponding message body, the...

  • EPSS 0.32%
  • Veröffentlicht 09.07.2026 00:00:00
  • Zuletzt bearbeitet 10.07.2026 17:41:47

An improper input handling vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.91) causes the device to abruptly terminate the TCP connection with a RST packet when a request containing an oversized field value is received, without ...

  • EPSS 0.41%
  • Veröffentlicht 09.07.2026 00:00:00
  • Zuletzt bearbeitet 10.07.2026 17:41:47

A stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.991) allows an unauthenticated remote attacker to cause a denial of service via a crafted TEARDOWN request.

  • EPSS 0.41%
  • Veröffentlicht 09.07.2026 00:00:00
  • Zuletzt bearbeitet 10.07.2026 17:41:47

A stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.91) allows an unauthenticated remote attacker to cause a denial of service via a crafted PLAY request.

Exploit
  • EPSS 4.48%
  • Veröffentlicht 06.06.2025 12:00:23
  • Zuletzt bearbeitet 29.04.2026 01:00:01

A vulnerability has been found in Tenda CP3 11.10.00.2311090948 and classified as critical. Affected by this vulnerability is the function sub_F3C8C of the file apollo. The manipulation leads to command injection. The attack can be launched remotely....