Tenda
Tenda CP3: vulnerabilidades y CVE
Tenda CP3 tiene 16 vulnerabilidades publicadas, 16 de ellas en los últimos 12 meses. 5 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE16
Últimos 12 meses16
Críticas5
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-86153 | Crítica (9.4) | 0.71% | — | 6 sept 2026 | A vulnerability has been found in Tenda CP3 27.5.57.101. This affects the function CRedirServer::SetRedirectEnable of the file Functions/Redirect.cpp. The manipulation leads to improper privilege management. Remote… |
| CVE-2026-86152 | Crítica (10) | 2.9% | — | 6 sept 2026 | A flaw has been found in Tenda CP3 27.5.57.101. The impacted element is the function CAutoAddWifi::ThreadProc of the file Functions/AutoAddWifi.cpp of the component Kylin. Executing a manipulation can lead to os command… |
| CVE-2026-86151 | Crítica (9.4) | 2.9% | — | 6 sept 2026 | A vulnerability was detected in Tenda CP3 27.5.57.101. The affected element is the function sub_2F77E8 of the file Apis/system.c of the component Network Configuration Management. Performing a manipulation results in os… |
| CVE-2026-86150 | Baja (2) | 0.38% | — | 5 sept 2026 | A security vulnerability has been detected in Tenda CP3 27.5.57.101. Impacted is an unknown function of the file custom-x/softap/hostapd. Such manipulation of the argument wpa_passphrase leads to hard-coded credentials.… |
| CVE-2026-86149 | Crítica (9.4) | 2.9% | — | 5 sept 2026 | A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection.… |
| CVE-2026-86148 | Crítica (9.4) | 2.9% | — | 5 sept 2026 | A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in… |
| CVE-2026-19749 | Baja (2.9) | 0.63% | — | 13 ago 2026 | A vulnerability was detected in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C and TC3T15C up to 20260625. Affected by this vulnerability is an unknown functionality of the component RTSP/ONVIF.… |
| CVE-2026-19748 | Baja (2.9) | 0.49% | — | 13 ago 2026 | A security vulnerability has been detected in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C and TC3T15C up to 20260625. Affected is the function CWebSessionManager_ParseSession of the file… |
| CVE-2026-19747 | Alta (8.9) | 3.1% | — | 13 ago 2026 | A weakness has been identified in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C and TC3T15C up to 20260625. This impacts the function CAte::HandleCmd of the file Kylin of the component ATE Module.… |
| CVE-2026-51606 | Alta (7.5) | 0.46% | — | 9 jul 2026 | An improper input handling vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.91) causes the device to abruptly terminate the TCP connection with a RST packet when a request containing an oversized… |
| CVE-2026-51605 | Alta (7.5) | 0.57% | — | 9 jul 2026 | A stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.991) allows an unauthenticated remote attacker to cause a denial of service via a crafted TEARDOWN request. |
| CVE-2026-51604 | Alta (7.5) | 0.57% | — | 9 jul 2026 | A stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.91) allows an unauthenticated remote attacker to cause a denial of service via a crafted PLAY request. |
| CVE-2026-51603 | Alta (7.5) | 0.56% | — | 9 jul 2026 | A stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.91) allows an unauthenticated remote attacker to cause a denial of service via a crafted second SETUP request. After… |
| CVE-2026-51602 | Alta (7.5) | 0.56% | — | 9 jul 2026 | A stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.91) allows an unauthenticated remote attacker to cause a denial of service via a crafted SETUP request. The RTSP… |
| CVE-2026-51601 | Alta (7.5) | 0.57% | — | 9 jul 2026 | Tenda CP3 V3.0 firmware V31.1.9.91 contains a stack-based buffer overflow in the RTSP service. The device fails to validate the length of the clock= value in the Range header field when processing a PLAY request. An… |
| CVE-2026-51600 | Alta (7.5) | 0.57% | — | 9 jul 2026 | Tenda CP3 V3.0 firmware V31.1.9.91 does not validate the Content-Length header field in RTSP requests (including DESCRIBE, SETUP, and PLAY methods). When a request carrying a Content-Length header is received without a… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.