CVE-2023-30351
Description
Tenda CP3 IP Camera has a hard-coded root password stored with weak encryption, enabling remote or physical root access.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Tenda CP3 IP Camera has a hard-coded root password stored with weak encryption, enabling remote or physical root access.
Vulnerability
The Shenzen Tenda Technology IP Camera CP3 running firmware version V11.10.00.2211041355 contains a hard-coded root password that is stored using weak encryption (CWE-328, CWE-798). The password can be recovered by reversing the hash from the shadow file located in the Squashfs filesystem. This vulnerability allows attackers to gain root access via the TELNET service or the UART serial interface [1][2].
Exploitation
An attacker with network access to the TELNET service or physical access to the UART interface can exploit this vulnerability. The steps involve extracting the shadow file (e.g., from firmware or via physical access), reversing the weak hash to obtain the plaintext root password, and then authenticating via TELNET or UART to obtain a root shell [1][2].
Impact
Successful exploitation grants the attacker a root shell on the device, leading to full compromise of confidentiality, integrity, and availability. The attacker can view live video streams, modify device configuration, install malware, or use the camera as a pivot point within the network.
Mitigation
As of the publication date, no official patch has been released by the vendor. Users should consider disabling the TELNET service if possible, restricting network access to the device, and physically securing the device to prevent UART access. If the device is end-of-life, replacement with a supported model is recommended. This vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog as of this writing.
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Shenzen Tenda Technology/IP Camera CP3description
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.