CVE-2026-51600: High severity Tenda CP3 vulnerability
Tenda CP3 V3.0 firmware V31.1.9.91 does not validate the Content-Length header field in RTSP requests (including DESCRIBE, SETUP, and PLAY methods). When a request carrying a Content-Length header is received without a corresponding message body, the RTSP parser enters a persistent body-awaiting state, causing the affected TCP connection to become permanently non-functional. The device does not actively close the connection, resulting in a TCP resource leak. This issue can be exploited by an unauthenticated remote attacker to cause a denial-of-service condition.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-51600?
CVE-2026-51600 has a high severity score of 7.5 on the CVSS scale.
What vulnerability does CVE-2026-51600 describe?
CVE-2026-51600 describes a lack of validation for the Content-Length header in RTSP requests in Tenda CP3 V3.0 firmware.
How do I fix CVE-2026-51600?
To fix CVE-2026-51600, update the Tenda CP3 firmware to a version that addresses the Content-Length header validation issue.
What software is affected by CVE-2026-51600?
Tenda CP3 V3.0 firmware version V31.1.9.91 is affected by CVE-2026-51600.
What type of attacks can CVE-2026-51600 facilitate?
CVE-2026-51600 can facilitate Denial of Service attacks due to the persistent body-awaiting state of the RTSP parser.