VYPR

Cp3 Firmware

by Tenda

CVEs (10)

  • CVE-2023-30354CriMay 10, 2023
    risk 0.64cvss 9.8epss 0.00

    Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 does not defend against physical access to U-Boot via the UART: the Wi-Fi password is shown, and the hardcoded boot password can be inserted for console access.

  • CVE-2023-30353CriMay 10, 2023
    risk 0.64cvss 9.8epss 0.01

    Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 allows unauthenticated remote code execution via an XML document.

  • CVE-2023-30352CriMay 10, 2023
    risk 0.64cvss 9.8epss 0.01

    Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 was discovered to contain a hard-coded default password for the RTSP feed.

  • CVE-2023-23080CriFeb 27, 2023
    risk 0.64cvss 9.8epss 0.02

    Certain Tenda products are vulnerable to command injection. This affects Tenda CP7 Tenda CP7<=V11.10.00.2211041403 and Tenda CP3 v.10 Tenda CP3 v.10<=V20220906024_2025 and Tenda IT7-PCS Tenda IT7-PCS<=V2209020914 and Tenda IT7-LCS Tenda IT7-LCS<=V2209020914 and Tenda IT7-PRS…

  • CVE-2025-52364HigJul 9, 2025
    risk 0.49cvss 7.5epss 0.01

    Insecure Permissions vulnerability in Tenda CP3 Pro Firmware V22.5.4.93 allows the telnet service (telnetd) by default at boot via the initialization script /etc/init.d/eth.sh. This allows remote attackers to connect to the device s shell over the network, potentially without…

  • CVE-2023-30356HigMay 10, 2023
    risk 0.49cvss 7.5epss 0.00

    Missing Support for an Integrity Check in Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 allows attackers to update the device with crafted firmware

  • CVE-2023-30351HigMay 10, 2023
    risk 0.49cvss 7.5epss 0.00

    Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 was discovered to contain a hard-coded default password for root which is stored using weak encryption. This vulnerability allows attackers to connect to the TELNET service (or UART) by using the exposed credentials.

  • CVE-2025-52363MedJul 14, 2025
    risk 0.44cvss 6.8epss 0.00

    Tenda CP3 Pro Firmware V22.5.4.93 contains a hardcoded root password hash in the /etc/passwd file and /etc/passwd-. An attacker with access to the firmware image can extract and attempt to crack the root password hash, potentially obtaining administrative access

  • CVE-2024-24488MedFeb 7, 2024
    risk 0.36cvss 5.5epss 0.00

    An issue in Shenzen Tenda Technology CP3V2.0 V11.10.00.2311090948 allows a local attacker to obtain sensitive information via the password component.

  • CVE-2025-5763MedJun 6, 2025
    risk 0.31cvss 4.7epss 0.04

    A vulnerability has been found in Tenda CP3 11.10.00.2311090948 and classified as critical. Affected by this vulnerability is the function sub_F3C8C of the file apollo. The manipulation leads to command injection. The attack can be launched remotely. The exploit has been…