CVE-2026-51606: Input Validation
An improper input handling vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.91) causes the device to abruptly terminate the TCP connection with a RST packet when a request containing an oversized field value is received, without returning any RFC 2326-compliant error response. This behavior affects the request-line URL field and header field values across multiple RTSP request types.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-51606?
CVE-2026-51606 has a severity rating of high, with a CVSS score of 7.5.
What type of vulnerability is CVE-2026-51606?
CVE-2026-51606 is categorized as an improper input handling vulnerability in the RTSP service.
How do I fix CVE-2026-51606?
To address CVE-2026-51606, update the Tenda CP3 to the latest firmware version that resolves this vulnerability.
What devices are affected by CVE-2026-51606?
CVE-2026-51606 affects the Tenda CP3 devices running firmware version V31.1.9.91.
What could be the impact of exploiting CVE-2026-51606?
Exploiting CVE-2026-51606 may cause the device to abruptly terminate the TCP connection without proper error reporting.