CVE-2026-51606
the affected product
An improper input handling vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.91) causes the device to abruptly terminate the TCP connection with a RST packet when a request containing an oversized field value is received, without returning any RFC 2326-compliant error response. This behavior affects the request-line URL field and header field values across multiple RTSP request types.
- CVSS
- 7.5
- EPSS
- 0.32% 24.8% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.10