AUGUST 24, 2026
Live Feed
Back to database
Case File

CVE-2026-51606

HIGH · CVSS 7.5 EPSS 0.32% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-09 · Last synced 2026-08-08

CyberRota Analysis

AI-Generated

The RTSP service in Tenda CP3 V3.0 (firmware V31.1.9.91) is vulnerable due to improper input handling, allowing an attacker to disrupt the TCP connection by sending requests with oversized field values. This results in the device terminating connections unexpectedly, potentially leading to service interruptions. Organizations using this firmware should prioritize patching to mitigate the risk of denial-of-service attacks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-51606
Severity
HIGH
CVSS
7.5
EPSS
0.32%

Original NVD Description

An improper input handling vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.91) causes the device to abruptly terminate the TCP connection with a RST packet when a request containing an oversized field value is received, without returning any RFC 2326-compliant error response. This behavior affects the request-line URL field and header field values across multiple RTSP request types.