Tenda
Tenda CP3: vulnerabilities and CVEs
Tenda CP3 has 16 published vulnerabilities, 16 of them in the last 12 months. 5 are rated critical and 0 are listed by CISA as actively exploited.
CVEs16
Last 12 months16
Critical5
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-86153 | Critical (9.4) | 0.71% | — | Sep 6, 2026 | A vulnerability has been found in Tenda CP3 27.5.57.101. This affects the function CRedirServer::SetRedirectEnable of the file Functions/Redirect.cpp. The manipulation leads to improper privilege management. Remote… |
| CVE-2026-86152 | Critical (10) | 2.9% | — | Sep 6, 2026 | A flaw has been found in Tenda CP3 27.5.57.101. The impacted element is the function CAutoAddWifi::ThreadProc of the file Functions/AutoAddWifi.cpp of the component Kylin. Executing a manipulation can lead to os command… |
| CVE-2026-86151 | Critical (9.4) | 2.9% | — | Sep 6, 2026 | A vulnerability was detected in Tenda CP3 27.5.57.101. The affected element is the function sub_2F77E8 of the file Apis/system.c of the component Network Configuration Management. Performing a manipulation results in os… |
| CVE-2026-86150 | Low (2) | 0.38% | — | Sep 5, 2026 | A security vulnerability has been detected in Tenda CP3 27.5.57.101. Impacted is an unknown function of the file custom-x/softap/hostapd. Such manipulation of the argument wpa_passphrase leads to hard-coded credentials.… |
| CVE-2026-86149 | Critical (9.4) | 2.9% | — | Sep 5, 2026 | A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection.… |
| CVE-2026-86148 | Critical (9.4) | 2.9% | — | Sep 5, 2026 | A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in… |
| CVE-2026-19749 | Low (2.9) | 0.63% | — | Aug 13, 2026 | A vulnerability was detected in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C and TC3T15C up to 20260625. Affected by this vulnerability is an unknown functionality of the component RTSP/ONVIF.… |
| CVE-2026-19748 | Low (2.9) | 0.49% | — | Aug 13, 2026 | A security vulnerability has been detected in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C and TC3T15C up to 20260625. Affected is the function CWebSessionManager_ParseSession of the file… |
| CVE-2026-19747 | High (8.9) | 3.1% | — | Aug 13, 2026 | A weakness has been identified in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C and TC3T15C up to 20260625. This impacts the function CAte::HandleCmd of the file Kylin of the component ATE Module.… |
| CVE-2026-51606 | High (7.5) | 0.46% | — | Jul 9, 2026 | An improper input handling vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.91) causes the device to abruptly terminate the TCP connection with a RST packet when a request containing an oversized… |
| CVE-2026-51605 | High (7.5) | 0.57% | — | Jul 9, 2026 | A stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.991) allows an unauthenticated remote attacker to cause a denial of service via a crafted TEARDOWN request. |
| CVE-2026-51604 | High (7.5) | 0.57% | — | Jul 9, 2026 | A stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.91) allows an unauthenticated remote attacker to cause a denial of service via a crafted PLAY request. |
| CVE-2026-51603 | High (7.5) | 0.56% | — | Jul 9, 2026 | A stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.91) allows an unauthenticated remote attacker to cause a denial of service via a crafted second SETUP request. After… |
| CVE-2026-51602 | High (7.5) | 0.56% | — | Jul 9, 2026 | A stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.91) allows an unauthenticated remote attacker to cause a denial of service via a crafted SETUP request. The RTSP… |
| CVE-2026-51601 | High (7.5) | 0.57% | — | Jul 9, 2026 | Tenda CP3 V3.0 firmware V31.1.9.91 contains a stack-based buffer overflow in the RTSP service. The device fails to validate the length of the clock= value in the Range header field when processing a PLAY request. An… |
| CVE-2026-51600 | High (7.5) | 0.57% | — | Jul 9, 2026 | Tenda CP3 V3.0 firmware V31.1.9.91 does not validate the Content-Length header field in RTSP requests (including DESCRIBE, SETUP, and PLAY methods). When a request carrying a Content-Length header is received without a… |