Improper Input Handling in RTSP Service of Tenda CP3 Device
CVE-2026-51606
7.5HIGH
What is CVE-2026-51606?
The Tenda CP3 device's RTSP service is susceptible to an improper input handling flaw. When the device encounters a request with an oversized field value, it terminates the TCP connection with a Reset (RST) packet, failing to return a compliant error response as defined by RFC 2326. This issue can affect various RTSP request types, compromising the device's stability and potentially exposing it to further network vulnerabilities.