CVE-2026-51606
Last modified
CVE-2026-51606 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. An improper input handling vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.91) causes the device to abruptly terminate the TCP connection with a RST packet when a request containing an oversized field value is received, without returning any RFC 2326-compliant error response. This behavior affects the request-line URL field and header field values across multiple RTSP request types.. EPSS estimates a 0.32% chance of exploitation in the next 30 days.
Description
An improper input handling vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.91) causes the device to abruptly terminate the TCP connection with a RST packet when a request containing an oversized field value is received, without returning any RFC 2326-compliant error response. This behavior affects the request-line URL field and header field values across multiple RTSP request types.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| — | — | n/a |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-51606?
How severe is CVE-2026-51606?
How do I fix CVE-2026-51606?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-51600Tenda CP3 V3.0 firmware V31.1.9.91 does not validate the Con…7.5
- CVE-2026-51601Tenda CP3 V3.0 firmware V31.1.9.91 contains a stack-based bu…7.5
- CVE-2026-51602A stack-based buffer overflow vulnerability in the RTSP serv…7.5
- CVE-2026-51603A stack-based buffer overflow vulnerability in the RTSP serv…7.5
- CVE-2026-51604A stack-based buffer overflow vulnerability in the RTSP serv…7.5
- CVE-2026-51605A stack-based buffer overflow vulnerability in the RTSP serv…7.5
- CVE-2026-5161Improper link resolution before file access ('link following…8.8
- CVE-2026-51610Incorrect access control in the RebootSystem function of TOT…4.3
- CVE-2026-51611Incorrect access control in the startSlaveReboot function of…9.8
- CVE-2026-51613Incorrect access control in the getDeviceInfo function of TO…4.3
- CVE-2026-51614Incorrect access control in the getAccessDeviceCfg function …4.3
- CVE-2026-51615Incorrect access control in the getLanCfg function of TOTOLI…7.5
Are you affected by CVE-2026-51606?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
