VYPR

CP3

by Tenda

CVEs (16)

  • CVE-2026-86152CriSep 6, 2026
    risk 0.65cvss 10.0epss 0.02

    A flaw has been found in Tenda CP3 27.5.57.101. The impacted element is the function CAutoAddWifi::ThreadProc of the file Functions/AutoAddWifi.cpp of the component Kylin. Executing a manipulation can lead to os command injection. The attack may be launched remotely.

  • CVE-2023-23080CriFeb 27, 2023
    risk 0.64cvss 9.8epss 0.02

    Certain Tenda products are vulnerable to command injection. This affects Tenda CP7 Tenda CP7<=V11.10.00.2211041403 and Tenda CP3 v.10 Tenda CP3 v.10<=V20220906024_2025 and Tenda IT7-PCS Tenda IT7-PCS<=V2209020914 and Tenda IT7-LCS Tenda IT7-LCS<=V2209020914 and Tenda IT7-PRS…

  • CVE-2026-86153CriSep 6, 2026
    risk 0.59cvss 9.1epss 0.00

    A vulnerability has been found in Tenda CP3 27.5.57.101. This affects the function CRedirServer::SetRedirectEnable of the file Functions/Redirect.cpp. The manipulation leads to improper privilege management. Remote exploitation of the attack is possible.

  • CVE-2026-86151CriSep 6, 2026
    risk 0.59cvss 9.1epss 0.02

    A vulnerability was detected in Tenda CP3 27.5.57.101. The affected element is the function sub_2F77E8 of the file Apis/system.c of the component Network Configuration Management. Performing a manipulation results in os command injection. The attack may be initiated remotely.

  • CVE-2026-86149CriSep 5, 2026
    risk 0.59cvss 9.1epss 0.02

    A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.

  • CVE-2026-86148CriSep 5, 2026
    risk 0.59cvss 9.1epss 0.02

    A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack…

  • CVE-2023-30356HigMay 10, 2023
    risk 0.49cvss 7.5epss 0.00

    Missing Support for an Integrity Check in Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 allows attackers to update the device with crafted firmware

  • CVE-2025-5763MedJun 6, 2025
    risk 0.31cvss 4.7epss 0.05

    A vulnerability has been found in Tenda CP3 11.10.00.2311090948 and classified as critical. Affected by this vulnerability is the function sub_F3C8C of the file apollo. The manipulation leads to command injection. The attack can be launched remotely. The exploit has been…

  • CVE-2026-86150MedSep 5, 2026
    risk 0.27cvss 4.1epss 0.00

    A security vulnerability has been detected in Tenda CP3 27.5.57.101. Impacted is an unknown function of the file custom-x/softap/hostapd. Such manipulation of the argument wpa_passphrase leads to hard-coded credentials. The attack can be launched remotely. The exploit has been…

  • CVE-2026-51606HigJul 9, 2026
    risk 0.00cvss 7.5epss 0.00

    An improper input handling vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.91) causes the device to abruptly terminate the TCP connection with a RST packet when a request containing an oversized field value is received, without returning any RFC…

  • CVE-2026-51605HigJul 9, 2026
    risk 0.00cvss 7.5epss 0.01

    A stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.991) allows an unauthenticated remote attacker to cause a denial of service via a crafted TEARDOWN request.

  • CVE-2026-51604HigJul 9, 2026
    risk 0.00cvss 7.5epss 0.01

    A stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.91) allows an unauthenticated remote attacker to cause a denial of service via a crafted PLAY request.

  • CVE-2026-51603HigJul 9, 2026
    risk 0.00cvss 7.5epss 0.01

    A stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.91) allows an unauthenticated remote attacker to cause a denial of service via a crafted second SETUP request. After completing the OPTIONS, DESCRIBE, and a legitimate first SETUP…

  • CVE-2026-51602HigJul 9, 2026
    risk 0.00cvss 7.5epss 0.01

    A stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.91) allows an unauthenticated remote attacker to cause a denial of service via a crafted SETUP request. The RTSP service's second-stage URL routing parser fails to validate the…

  • CVE-2026-51601HigJul 9, 2026
    risk 0.00cvss 7.5epss 0.01

    Tenda CP3 V3.0 firmware V31.1.9.91 contains a stack-based buffer overflow in the RTSP service. The device fails to validate the length of the clock= value in the Range header field when processing a PLAY request. An unauthenticated remote attacker who has completed a standard…

  • CVE-2026-51600HigJul 9, 2026
    risk 0.00cvss 7.5epss 0.01

    Tenda CP3 V3.0 firmware V31.1.9.91 does not validate the Content-Length header field in RTSP requests (including DESCRIBE, SETUP, and PLAY methods). When a request carrying a Content-Length header is received without a corresponding message body, the RTSP parser enters a…