PatchSiren cyber security CVE debrief
CVE-2026-51606 Tenda CVE debrief
CVE-2026-51606 is a HIGH severity vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.91). The vulnerability causes the device to abruptly terminate the TCP connection with a RST packet when a request containing an oversized field value is received, without returning any RFC 2326-compliant error response. This behavior affects the request-line URL field and header field values across multiple RTSP request types. Affected product deployments should be identified and owners assigned for follow-up.
- Vendor
- Tenda
- Product
- CP3 V3.0 (firmware V31.1.9.91)
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-09
- Original CVE updated
- 2026-07-10
- Advisory published
- 2026-07-09
- Advisory updated
- 2026-07-10
Who should care
Users of Tenda CP3 V3.0 (firmware V31.1.9.91) should be aware of this vulnerability and take necessary precautions to prevent exploitation. This includes confirming whether affected product deployments exist in managed environments and assigning an owner for follow-up. Additionally, users should review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance. They should also plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
Technical summary
The vulnerability is caused by improper input handling in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.91). When a request with an oversized field value is received, the device terminates the TCP connection with a RST packet without returning an RFC 2326-compliant error response. This affects the request-line URL field and header field values across multiple RTSP request types. The vulnerability has a CVSS score of 7.5 and is considered HIGH severity. Users of Tenda CP3 V3.0 (firmware V31.1.9.91) should be aware of this vulnerability and take necessary precautions to prevent exploitation.
Defensive priority
High priority should be given to patching or mitigating this vulnerability, as it could potentially be exploited to disrupt RTSP service on affected devices. Monitoring and compensating controls are recommended while remediation is scheduled and verified. Review vendor-supported updates or mitigations through normal change control where exposure is confirmed. Track exceptions, retest remediated assets, and close the item only after evidence is documented. Consider implementing additional security controls, such as network segmentation or intrusion detection, to further protect against potential exploitation. Limit access to the RTSP service to trusted networks or IP addresses to reduce the attack surface. Users of Tenda CP3 V3.0 (firmware V31.1.9.91) should be aware of this vulnerability and take necessary precautions to prevent exploitation. Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up. Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed. Review compensating controls for exposed systems while remediation is scheduled and verified. Check relevant monitoring, detection, and logs for exposed assets that need extra review. Track exceptions, retest remediated assets, and close the item only after evidence is documented. This vulnerability has a CVSS score of 7.5 and is considered HIGH severity. The vulnerability is caused by improper input handling in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.91). When a request with an oversized field value is received, the device terminates the TCP connection with a RST packet without returning an RFC 2326-compliant error response. This affects the request-line URL field and header field values across multiple RTSP request types. Users of Tenda CP3 V3.0 (firmware V31.1.9.91) should be aware of this vulnerability and take necessary precautions to prevent exploitation. The CVE record was published on 2026-07-09T17:17:01.173Z and last modified on 2026-07-10T17:41:47.303Z. The NVD entry is currently Deferred. Evidence is limited to CVE and NVD information. Defenders should verify affected product deployments,
Recommended defensive actions
- Apply the latest firmware update for Tenda CP3 V3.0
- Limit access to the RTSP service to trusted networks or IP addresses
- Monitor RTSP service logs for unusual activity
- Consider implementing additional security controls, such as network segmentation or intrusion detection
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record was published on 2026-07-09T17:17:01.173Z and last modified on 2026-07-10T17:41:47.303Z. The NVD entry is currently Deferred. Evidence is limited to CVE and NVD information. Defenders should verify affected product deployments and review official advisories for validation.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-51606 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-51606
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-51606 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-51606
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/kkkk2222874/cve_ID_report/blob/main/Tenda_CP3_V3.0/Tenda_CP3_V3.0_5th/README.md
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.